<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>赵健在这里！ &#187; patch</title>
	<atom:link href="http://www.zhaojian.net/tag/patch/feed" rel="self" type="application/rss+xml" />
	<link>http://www.zhaojian.net</link>
	<description>专注于Linux&#124;Apache&#124;MySQL&#124;PHP等开源技术的学习与研究</description>
	<lastBuildDate>Mon, 23 Aug 2010 02:57:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>lighttpd 1.4.x 爆高危漏洞</title>
		<link>http://www.zhaojian.net/diannaowangluo/lighttpd-1-4-x-bao-gao-wei-lou-dong.html</link>
		<comments>http://www.zhaojian.net/diannaowangluo/lighttpd-1-4-x-bao-gao-wei-lou-dong.html#comments</comments>
		<pubDate>Tue, 09 Feb 2010 02:15:45 +0000</pubDate>
		<dc:creator>赵健</dc:creator>
				<category><![CDATA[电脑网络]]></category>
		<category><![CDATA[2003]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[lighttpd]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[web服务器]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[服务器]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.zhaojian.net/?p=666</guid>
		<description><![CDATA[lighttpd(发音为lighty)是一套开放源代码的网页服务器,以BSD许可证放出.相较于其他的网页服务 器,lighttpd仅需少量的 内存及CPU资源即可达到同样的效能.今天lighttpd 张贴公告修复了一个已知的严重bug.可能会给 DoS/OOM 攻击以可乘之机.Li Ming （貌似是国人） reported a serious bug in lighttpd: If you send the request data very slow (e.g. sleep 0.01 after each byte), lighttpd will easily use all available memory and die (especially for parallel requests), allowing a DoS within minutes. See: lighttpd_sa_2010_01.txt (安全公告内文) Bug #2147 The bug is tracked [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.zhaojian.net/tag/lighttpd" class="st_tag internal_tag" rel="tag" title="Posts tagged with lighttpd">lighttpd</a>(发音为lighty)是一套开放源代码的网页<span class='wp_keywordlink_affiliate'><a href="http://www.zhaojian.net/tag/%e6%9c%8d%e5%8a%a1%e5%99%a8" title="查看 服务器 的全部文章" target="_blank">服务器</a></span>,以BSD许可证放出.相较于其他的网页服务 器,<a href="http://www.zhaojian.net/tag/lighttpd" class="st_tag internal_tag" rel="tag" title="Posts tagged with lighttpd">lighttpd</a>仅需少量的 内存及CPU资源即可达到同样的效能.今天<a href="http://www.zhaojian.net/tag/lighttpd" class="st_tag internal_tag" rel="tag" title="Posts tagged with lighttpd">lighttpd</a> 张贴公告修复了一个已知的严重bug.可能会给  <a href="http://www.zhaojian.net/tag/dos" class="st_tag internal_tag" rel="tag" title="Posts tagged with dos">DoS</a>/OOM 攻击以可乘之机.Li Ming （貌似是国人） reported a serious bug in <a href="http://www.zhaojian.net/tag/lighttpd" class="st_tag internal_tag" rel="tag" title="Posts tagged with lighttpd">lighttpd</a>:</p>
<p>If you send the request data very slow (e.g. sleep <a href="http://www.zhaojian.net/tag/2003" class="st_tag internal_tag" rel="tag" title="Posts tagged with 0">0</a>.01  after each byte), <a href="http://www.zhaojian.net/tag/lighttpd" class="st_tag internal_tag" rel="tag" title="Posts tagged with lighttpd">lighttpd</a> will easily use all available memory and die  (especially for parallel requests), allowing a <a href="http://www.zhaojian.net/tag/dos" class="st_tag internal_tag" rel="tag" title="Posts tagged with dos">DoS</a> within minutes.<br />
See:</p>
<ul>
<li><a href="http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2010_01.txt">lighttpd_sa_2010_01.txt</a> (安全公告内文)</li>
<li><a href="http://redmine.lighttpd.net/issues/2147">Bug #2147</a></li>
</ul>
<p>The  bug is tracked as CVE-2010-0295.</p>
<p>As far as we know all versions  are affected.</p>
<p>该<span class='wp_keywordlink_affiliate'><a href="http://www.zhaojian.net/tag/%e6%bc%8f%e6%b4%9e" title="查看 漏洞 的全部文章" target="_blank">漏洞</a></span>影响1.4.26以下 和  r2710 之前的所有<a href="http://www.zhaojian.net/tag/lighttpd" class="st_tag internal_tag" rel="tag" title="Posts tagged with lighttpd">lighttpd</a>版本.如果你正在使用的话，</p>
<p>可 以选择<a href="http://www.zhaojian.net/tag/patch" class="st_tag internal_tag" rel="tag" title="Posts tagged with patch">patch</a> 修复.</p>
<p>补丁下载：</p>
<p><a href="http://download.lighttpd.net/lighttpd/security/lighttpd-1.4.x_fix_slow_request_dos.patch" target="_blank">http://download.lighttpd.net/lighttpd/security/lighttpd-1.4.x_fix_slow_request_dos.patch</a> (适用于1.4.x)<br />
<a href="http://download.lighttpd.net/lighttpd/security/lighttpd-1.5_fix_slow_request_dos.patch" target="_blank">http://download.lighttpd.net/lighttpd/security/lighttpd-1.5_fix_slow_request_dos.patch</a> (适用于1.5.x)</p>

	标签：<a href="http://www.zhaojian.net/tag/2003" title="2003" rel="tag">2003</a>, <a href="http://www.zhaojian.net/tag/dos" title="dos" rel="tag">dos</a>, <a href="http://www.zhaojian.net/tag/lighttpd" title="lighttpd" rel="tag">lighttpd</a>, <a href="http://www.zhaojian.net/tag/patch" title="patch" rel="tag">patch</a>, <a href="http://www.zhaojian.net/tag/web%e6%9c%8d%e5%8a%a1%e5%99%a8" title="web服务器" rel="tag">web服务器</a>, <a href="http://www.zhaojian.net/tag/windows" title="windows" rel="tag">windows</a>, <a href="http://www.zhaojian.net/tag/%e6%9c%8d%e5%8a%a1%e5%99%a8" title="服务器" rel="tag">服务器</a>, <a href="http://www.zhaojian.net/tag/%e6%bc%8f%e6%b4%9e" title="漏洞" rel="tag">漏洞</a><br />

	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.zhaojian.net/jishusuibi/verycd-easymuleche-di-qu-chu-ed2kfu-wu-qi-he-kadwang-luo-sou-suo.html" title="VeryCD easyMule彻底去除eD2k服务器和Kad网络搜索 (2010年06月22日)">VeryCD easyMule彻底去除eD2k服务器和Kad网络搜索</a> (0)</li>
	<li><a href="http://www.zhaojian.net/linuxjishu/windows-xia-de-apache-php-mysql-lvse-huanjing-taojian-bao-phpnow-1-5-5-fabu.html" title="Windows下的Apache+PHP+MySQL绿色环境套件包PHPnow1.5.5发布 (2010年02月8日)">Windows下的Apache+PHP+MySQL绿色环境套件包PHPnow1.5.5发布</a> (1)</li>
	<li><a href="http://www.zhaojian.net/linuxjishu/hei-ke-zai-bao-linuxnei-he-gao-wei-lou-dong-yi-ge-ming-ling-ke-yi-gong-ji-suo-you-linuxxi-tong.html" title="黑客再爆Linux内核高危漏洞，一个命令可以攻击所有Linux系统 (2009年08月17日)">黑客再爆Linux内核高危漏洞，一个命令可以攻击所有Linux系统</a> (0)</li>
	<li><a href="http://www.zhaojian.net/diannaowangluo/wei-ruan-adobe-pdflou-dong-zai-ci-bei-li-yong.html" title="微软：Adobe PDF漏洞再次被利用 (2010年03月12日)">微软：Adobe PDF漏洞再次被利用</a> (0)</li>
	<li><a href="http://www.zhaojian.net/diannaowangluo/windows-2003-xia-an-zhuang-avira-antivirxiao-hong-san-guan-fang-jian-ti-zhong-wen-ban.html" title="Windows 2003 下安装 Avira AntiVir（小红伞）官方简体中文版 (2010年02月18日)">Windows 2003 下安装 Avira AntiVir（小红伞）官方简体中文版</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.zhaojian.net/diannaowangluo/lighttpd-1-4-x-bao-gao-wei-lou-dong.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->