lighttpd: security bump to version 1.14.51
authorPeter Korsgaard <peter@korsgaard.com>
Tue, 30 Oct 2018 10:21:51 +0000 (11:21 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 30 Oct 2018 20:05:13 +0000 (21:05 +0100)
commit15793bc19f196691f6b09636ebf2c3de53d369c0
tree3d9b236b820a1c7c98b289178980ee3df872a3fb
parent0646d67c1d8e5ba4a1376a215d0c7e69751835df
lighttpd: security bump to version 1.14.51

Fixes the following security issues:

1.4.50:
[mod_alias] security: potential path traversal with specific configs
[core] security: use-after-free invalid Range req
[mod_alias] security: path traversal in mod_alias (in some use cases) (fixes #2898)
[core] security: use-after-free after invalid Range request (fixes #2899)

1.4.51:
[core,security] process headers after combining folded headers
[mod_userdir] security: skip username “.” and “..”

1.4.51 brings optional pam and wolfssl support.  Explicitly disable these
options for now.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/lighttpd/lighttpd.hash
package/lighttpd/lighttpd.mk