Your message dated Tue, 01 Sep 2026 16:19:30 +0000
with message-id <[email protected]>
and subject line Bug#1144953: fixed in mini-httpd 1.30-18
has caused the Debian Bug report #1144953,
regarding mini-httpd: CVE-2026-68005
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144953: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144953
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: mini-httpd
Version: 1.30-17
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 1.30-13

Hi,

The following vulnerability was published for mini-httpd.

CVE-2026-68005[0]:
| An issue in ACME mini_httpd 1.30 and prior allows a remote attacker
| to cause a denial of service via the HTTP request header parser in
| the handle_request() function


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-68005
    https://www.cve.org/CVERecord?id=CVE-2026-68005

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: mini-httpd
Source-Version: 1.30-18
Done: Alexandru Mihail <[email protected]>

We believe that the bug you reported is fixed in the latest version of
mini-httpd, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alexandru Mihail <[email protected]> (supplier of updated 
mini-httpd package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 01 Sep 2026 18:05:13 +0300
Source: mini-httpd
Architecture: source
Version: 1.30-18
Distribution: unstable
Urgency: high
Maintainer: Alexandru Mihail <[email protected]>
Changed-By: Alexandru Mihail <[email protected]>
Closes: 1144953
Changes:
 mini-httpd (1.30-18) unstable; urgency=high
 .
   * Fix memory exhaustion DoS in header parsing (CVE-2026-68005).
     (Closes: #1144953)
   * Fix potential Slowloris in the same place by removing old alarm(60)
     based timeout mechanism.
   * Update copyright year on debian/
Checksums-Sha1:
 0f936175a6619bdfbd865ca73560ad3145c2160d 1887 mini-httpd_1.30-18.dsc
 4ddd572bccde679348bd18dbde9087c7563fa2a2 23092 mini-httpd_1.30-18.debian.tar.xz
 eb09ffd310c0064df22f772b70db5a19b68a303e 6801 
mini-httpd_1.30-18_source.buildinfo
Checksums-Sha256:
 29d2f05fb2734a25fd75065540bc4f01a52bf739bce71b04f103fcbb91c18898 1887 
mini-httpd_1.30-18.dsc
 f28744540cd46dbb227b60cfbb5534b37e89e548b3979818c812450cf8c1122f 23092 
mini-httpd_1.30-18.debian.tar.xz
 6540d66db3df5c3a1225b5fa06631e84395e3d0e4f57e7870cabb1d6188eb42f 6801 
mini-httpd_1.30-18_source.buildinfo
Files:
 3ab9e698e54b52c6bfad785271f1e0a1 1887 web optional mini-httpd_1.30-18.dsc
 7010b73a0d4bb75a2b93935eb997d9f0 23092 web optional 
mini-httpd_1.30-18.debian.tar.xz
 c12dba094eca6cbbda7e159d2adb340c 6801 web optional 
mini-httpd_1.30-18_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXHq+og+GMEWcyMi14n8s+EWML6QFAmqW+G4ACgkQ4n8s+EWM
L6S8EQ/+NrGYBheLMe9xMszIG6T6zBprj0Ev5ipDIplWGRrVEBdXCqVouJOSEP37
SIIgs4rwM5wpFW1xRaHc9zber05wzCxwjIgJqlzbz4FyqlnyRxyqLaC2tf4KIOQf
0HXbnWlMpCj5XVHLzBb/1TjJElHjRbeEktj1dJIWgZtJqE35UNenP0Qa/7IT0mv+
hZ9KRVZFKbtAyXuWtvaB/jiiSTMA937eJKJZaGu2CwkmSqZ1IY2Bg0aal9EBMHch
Cqv+0Z2Eva7cz3uUCxX2Q8R1IpAVSyMYOg1iWI1hL/7FbWmKvCy/dakoJJHdLsZW
L4KsFJWxjzYg4HUzTgOt5ZkgyV+vWFMSSjTdepT7LV0rF+CEraBM2bM4gL7gMscm
X8iaFZw2/DhWLHU3cdNW4s4EDgIBoA1uQ2TVOgmOgTh54bpcaddpsVP+jWEy+u8h
vsy5tmMoDZtNIWMrrQCyTwb5LbND4Q2NbnKKpK2EnyAzlqFGUEdikih4penGIxWT
XaZFF93PtR+uBwEuSIM1Aq7y1KmGLaL0vJdXINXIZlkgtBzPLIkR90zXTraOSW54
jqIUCZneHKrEg8CQz6b5c29xdSPb9EMmqWTzGsheiM10DtjulPqXl7pGpW1feu1m
jIks6eNQmT7heH8zEpjILnqL0tpjXwLK4w0TCgqtHcAvk/TA14o=
=+m2E
-----END PGP SIGNATURE-----

Attachment: pgpKilC_zU631.pgp
Description: PGP signature


--- End Message ---

Reply via email to