CVE-2008-4359
published 2008-10-03CVE-2008-4359: lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.35%
90.2th percentile
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | lighttpd | < lighttpd 1.4.19-5 (bookworm) | lighttpd 1.4.19-5 (bookworm) |
| lighttpd | lighttpd | < 1.4.20 | 1.4.20 |
| lighttpd | lighttpd | >= 0 < 1.4.19-5 | 1.4.19-5 |
| lighttpd | lighttpd | >= 0 < 1.4.19-5 | 1.4.19-5 |
| lighttpd | lighttpd | >= 0 < 1.4.19-5 | 1.4.19-5 |
| lighttpd | lighttpd | >= 0 < 1.4.19-5 | 1.4.19-5 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q628-fxxh-w8xf: lighttpd before 1
ghsa_unreviewed·2022-05-02
CVE-2008-4359 [HIGH] CWE-200 GHSA-q628-fxxh-w8xf: lighttpd before 1
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
OSV
CVE-2008-4359: lighttpd before 1
osv·2008-10-03·CVSS 7.5
CVE-2008-4359 [HIGH] CVE-2008-4359: lighttpd before 1
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Red Hat
lighttpd: bypass of rewrite/redirect rules using encoded urls
vendor_redhat·2008-07-14·CVSS 7.5
CVE-2008-4359 [HIGH] lighttpd: bypass of rewrite/redirect rules using encoded urls
lighttpd: bypass of rewrite/redirect rules using encoded urls
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Debian
CVE-2008-4359: lighttpd - lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2)...
vendor_debian·2008·CVSS 7.5
CVE-2008-4359 [HIGH] CVE-2008-4359: lighttpd - lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2)...
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Scope: local
bookworm: resolved (fixed in 1.4.19-5)
bullseye: resolved (fixed in 1.4.19-5)
forky: resolved (fixed in 1.4.19-5)
sid: resolved (fixed in 1.4.19-5)
trixie: resolved (fixed in 1.4.19-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-4359 lighttpd: bypass of rewrite/redirect rules using encoded urls
bugzilla·2008-10-06·CVSS 7.5
CVE-2008-4359 [HIGH] CVE-2008-4359 lighttpd: bypass of rewrite/redirect rules using encoded urls
CVE-2008-4359 lighttpd: bypass of rewrite/redirect rules using encoded urls
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4359 to the following vulnerability:
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and
(2) url.rewrite configuration settings before performing URL decoding, which
might allow remote attackers to bypass intended access restrictions, and obtain
sensitive information or possibly modify data.
Affected versions:
all versions before 1.4.20 (1.5 before r2310)
Upstream advisory:
http://www.lighttpd.net/security/lighttpd_sa_2008_05.txt
Upstream bug report:
http://trac.lighttpd.net/trac/ticket/1720
Upstream patches (1.4.x):
http://www.lighttpd.net/security/lighttpd-1.4.x_rewrite_redirect_decode_url.patch
http://trac.lighttp
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 8]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 8]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%208&bugs=464638,
---
New bodhi link:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%208&bugs=464638,CVE-2008-4298,CVE-2008-4359,CVE-2008-4360
---
This message is a reminder that Fedora 8 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 8. It is Fedora's policy to close all
bu
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-4]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-4]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-4]
epel-4 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
I had forgotten to close this report, doing so now.
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-5]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-5]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-5]
epel-5 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
I had forgotten to close this report, doing so now.
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 9]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 9]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=464639,
---
New bodhi link:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=464639,CVE-2008-4298,CVE-2008-4359,CVE-2008-4360
---
lighttpd-1.4.20-6.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/lighttpd-1.4.20-6.fc9
---
lighttpd-1.4.20-6.fc9 has been pushed to the Fedora 9 testing repository.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://openwall.com/lists/oss-security/2008/09/30/1http://openwall.com/lists/oss-security/2008/09/30/2http://openwall.com/lists/oss-security/2008/09/30/3http://secunia.com/advisories/32069http://secunia.com/advisories/32132http://secunia.com/advisories/32480http://secunia.com/advisories/32834http://secunia.com/advisories/32972http://security.gentoo.org/glsa/glsa-200812-04.xmlhttp://trac.lighttpd.net/trac/changeset/2278http://trac.lighttpd.net/trac/changeset/2307http://trac.lighttpd.net/trac/changeset/2309http://trac.lighttpd.net/trac/changeset/2310http://trac.lighttpd.net/trac/ticket/1720http://wiki.rpath.com/Advisories:rPSA-2008-0309http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309http://www.debian.org/security/2008/dsa-1645http://www.lighttpd.net/security/lighttpd-1.4.x_rewrite_redirect_decode_url.patchhttp://www.lighttpd.net/security/lighttpd_sa_2008_05.txthttp://www.securityfocus.com/archive/1/497932/100/0/threadedhttp://www.securityfocus.com/bid/31599http://www.vupen.com/english/advisories/2008/2741https://exchange.xforce.ibmcloud.com/vulnerabilities/45690http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://openwall.com/lists/oss-security/2008/09/30/1http://openwall.com/lists/oss-security/2008/09/30/2http://openwall.com/lists/oss-security/2008/09/30/3http://secunia.com/advisories/32069http://secunia.com/advisories/32132http://secunia.com/advisories/32480http://secunia.com/advisories/32834http://secunia.com/advisories/32972http://security.gentoo.org/glsa/glsa-200812-04.xmlhttp://trac.lighttpd.net/trac/changeset/2278http://trac.lighttpd.net/trac/changeset/2307http://trac.lighttpd.net/trac/changeset/2309http://trac.lighttpd.net/trac/changeset/2310http://trac.lighttpd.net/trac/ticket/1720http://wiki.rpath.com/Advisories:rPSA-2008-0309http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309http://www.debian.org/security/2008/dsa-1645http://www.lighttpd.net/security/lighttpd-1.4.x_rewrite_redirect_decode_url.patchhttp://www.lighttpd.net/security/lighttpd_sa_2008_05.txthttp://www.securityfocus.com/archive/1/497932/100/0/threadedhttp://www.securityfocus.com/bid/31599http://www.vupen.com/english/advisories/2008/2741https://exchange.xforce.ibmcloud.com/vulnerabilities/45690
2008-10-03
Published