URL: https://linuxfr.org/forums/linux-debian-ubuntu/posts/vulnerabilite-high-sur-maj-debian-7-1-wtf Title: Vulnérabilité = high sur maj debian 7.1 : WTF ?! Authors: Kwiknclean Date: 2013年07月04日T21:12:01+02:00 License: CC By-SA Tags: vulnérabilité, debian, bug et update Score: 0 Salut linuxFR. Voilà je viens tous juste de migrer de squeeze vers wheezy sur mon serveur web, et voici ce que contenait le rapport des changements en début d'installation. Il débute sympathiquement par deux grosses urgency=high et medium sur lighttpd (que j'utilise pour m'héberger ... sympa). A ce propos j'ai été obligé d'utiliser les miroirs Allemands pour l'update car sur les miroirs français je téléchargeais à quelque chose comme 5 253 **B/s** ... et plus de 9**M/s** sur les Allemands .. (et ce n'est pas la première fois). lighttpd (1.4.31-4) unstable; urgency=high The default Debian configuration file for PHP invoked from FastCGI was vulnerable to local symlink attacks and race conditions when an attacker manages to control the PHP socket file (/tmp/php.socket up to 1.4.31-3) before the web server started. Possibly the web server could have been tricked to use a forged PHP. The problem lies in the configuration, thus this update will fix the problem only if you did not modify the file /etc/lighttpd/conf-available/15-fastcgi-php.conf If you did, dpkg will not overwrite your changes. Please make sure to set "socket" => "/var/run/lighttpd/php.socket" yourself in that case. -- Arno Töll 2013年3月14日 01:57:42 +0100 lighttpd (1.4.30-1) unstable; urgency=medium This releases includes an option to force Lighttpd to honor the cipher order in ssl.cipher-list. This mitigates the effects of a SSL CBC attack commonly referred to as "BEAST attack". See [1] and CVE-2011-3389 for more details. To minimze the risk of this attack it is recommended either to disable all CBC ciphers (beware: this will break reasonably old clients or those who support CBC ciphers only), or pursue clients to use safe ciphers where possible at least. To do so, set ssl.cipher-list = "ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM" ssl.honor-cipher-order = "enable" in your /etc/lighttpd/conf-available/10-ssl.conf file or on any SSL enabled host you configured. If you did not change this file previously, this upgrade will update it automatically. [1] http://blog.ivanristic.com/2011/10/mitigating-the-beast-attack-on-tls.html -- Arno Töll 2011年12月18日 20:26:50 +0100 Si quelqu'un pouvait m'expliquer exactement de quoi il en retourne, je pensais que les "stables" figeaient les paquets stables longtemps en avance pour éviter ce genre de déconvenues ... moi plus trop bien comprendre là.

AltStyle によって変換されたページ (->オリジナル) /