SuSE: 2014:0474-1: important: lighttpd
Summary
The HTTP server lighttpd was updated to fix the following
security issues:
* CVE-2014-2323: SQL injection vulnerability in
mod_mysql_vhost.c in lighttpd allowed remote attackers to
execute arbitrary SQL commands via the host name.
* CVE-2014-2323: Multiple directory traversal
vulnerabilities in mod_evhost and mod_simple_vhost in
lighttpd allowed remote attackers to read arbitrary files
via .. (dot dot) in the host name.
More information can be found on the lighttpd advisory
page:
014_01.txt
References
#867350
Cross- CVE-2014-2323 CVE-2014-2324
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP3
SUSE Linux Enterprise High Availability Extension 11 SP3
https://www.suse.com/security/cve/CVE-2014-2323.html
https://www.suse.com/security/cve/CVE-2014-2324.html
https://bugzilla.novell.com/867350
https://scc.suse.com:443/patches/