Debian: New lighttpd packages fix CGI source disclosure


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) Debian: New lighttpd packages fix CGI source disclosure
# 1  
Old 03-06-2008
Debian: New lighttpd packages fix CGI source disclosure

LinuxSecurity.com: It was discovered that lighttpd, a fast webserver with minimal memory footprint, would display the source to CGI scripts if their execution failed in some circumstances.

More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
cgi_cookie_authority(3) 					     cgi/cgi.h						   cgi_cookie_authority(3)

NAME
cgi_cookie_authority - determine the cookie authority for a domain SYNOPSIS
#include <cgi/cgi.h> char *cgi_cookie_authority (CGI *cgi, const char *host); ARGUMENTS
cgi - a CGI struct host - optional host to match against. If NULL, the function will use the HTTP.Host HDF variable. DESCRIPTION
cgi_cookie_authority will walk the CookieAuthority portion of the CGI HDF data set, and return the matching domain if it exists. The pur- pose of this is so that you set domain specific cookies. For instance, you might have CookieAuthority.0 = neotonic.com In which case, any webserver using a hostname ending in neotonic.com will generate a cookie authority of neotonic.com. RETURN VALUE
None SEE ALSO
cgi_debug_init(3), cgi_parse(3), cgi_destroy(3), cgi_js_escape(3), cgi_html_escape_strfunc(3), cgi_register_strfuncs(3), cgi_output(3), parse_rfc2388(3), cgi_url_validate(3), open_upload(3), cgi_cs_init(3), cgi_url_escape_more(3), cgi_html_strip_strfunc(3), cgi_neo_error(3), cgi_redirect(3), cgi_filehandle(3), cgi_register_parse_cb(3), cgi_url_escape(3), cgi_init(3), cgi_redirect_uri(3), cgi_cookie_clear(3), cgi_url_unescape(3), cgi_vredirect(3), cgi_display(3), cgi_html_ws_strip(3), cgi_error(3), cgi_cookie_set(3), cgi_text_html_strfunc(3), cgi_cookie_authority ClearSilver 12 July 2007 cgi_cookie_authority(3)