cbcvebase.
CVE-2007-3946
published 2007-07-24

CVE-2007-3946: mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a…

PriorityP422medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
3.42%
87.7th percentile
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlighttpd< lighttpd 1.4.16-1 (bookworm)lighttpd 1.4.16-1 (bookworm)
lighttpdlighttpd<= 1.4.15
lighttpdlighttpd>= 0 < 1.4.16-11.4.16-1
lighttpdlighttpd>= 0 < 1.4.16-11.4.16-1
lighttpdlighttpd>= 0 < 1.4.16-11.4.16-1
lighttpdlighttpd>= 0 < 1.4.16-11.4.16-1

CVSS provenance

nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.