Debian Lighttpd vulnerabilities
37 known vulnerabilities affecting debian/lighttpd.
Total CVEs
37
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH7MEDIUM16LOW11UNKNOWN1
Vulnerabilities
Page 1 of 2
CVE-2009-3555P1MEDIUMCVSS 5.8ExploitedPoCfixed in apache2 2.2.14-2 (bookworm)2009
CVE-2009-3555 [MEDIUM] CVE-2009-3555: apache2 - The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Micr...
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate reneg
debian
CVE-2014-2323P1CRITICALCVSS 9.8PoCfixed in lighttpd 1.4.33-1+nmu3 (bookworm)2014
CVE-2014-2323 [CRITICAL] CVE-2014-2323: lighttpd - SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allow...
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
Scope: local
bookworm: resolved (fixed in 1.4.33-1+nmu3)
bullseye: resolved (fixed in 1.4.33-1+nmu3)
forky: resolved (fixed in 1.4.33-1+nmu3)
sid: resolved (fixed in 1.4.33-1+nmu
debian
CVE-2014-3566P3LOWCVSS 3.4PoCfixed in erlang 1:17.3-dfsg-3 (bookworm)2014
CVE-2014-3566 [LOW] CVE-2014-3566: bouncycastle - The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses...
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2011-3389P3MEDIUMCVSS 4.3PoCfixed in asterisk 1:13.7.2~dfsg-1 (bullseye)2011
CVE-2011-3389 [MEDIUM] CVE-2011-3389: asterisk - The SSL protocol, as used in certain configurations in Microsoft Windows and Mic...
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS s
debian
CVE-2019-11072P3CRITICALCVSS 9.8fixed in lighttpd 1.4.53-4 (bookworm)2019
CVE-2019-11072 [CRITICAL] CVE-2019-11072: lighttpd - lighttpd before 1.4.54 has a signed integer overflow, which might allow remote a...
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F? in burl_normalize_2F_to_slash_fix in burl.c. NOTE: The developer states "The feature which can be abused to c
debian
CVE-2022-30780P3HIGHCVSS 7.5fixed in lighttpd 1.4.59-1 (bookworm)2022
CVE-2022-30780 [HIGH] CVE-2022-30780: lighttpd - Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of ser...
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.
Scope: local
bookworm: resolved (fixed in 1.4.59-1)
bullseye: resolved (fixed in 1.4.59-1)
forky: resolved (fixed
debian
CVE-2011-4362P3LOWCVSS 5.0PoCfixed in lighttpd 1.4.30-1 (bookworm)2011
CVE-2011-4362 [MEDIUM] CVE-2011-4362: lighttpd - Integer signedness error in the base64_decode function in the HTTP authenticatio...
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via crafted base64 input that triggers an out-of-bounds read with a negative index.
Scope: local
bookworm: resolved (fix
debian
CVE-2008-1270P4MEDIUMCVSS 5.0PoCfixed in lighttpd 1.4.19-1 (bookworm)2008
CVE-2008-1270 [MEDIUM] CVE-2008-1270: lighttpd - mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a...
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.
Scope: local
bookworm: resolved (fixed in 1.4.19-1)
bullseye: resolved (fixed in 1.4.19-1)
forky: resolved (fixed in 1.4.19-1)
sid: resolved (fixed in 1.4.1
debian
CVE-2010-0295P4MEDIUMCVSS 5.0PoCfixed in lighttpd 1.4.26-1 (bookworm)2010
CVE-2010-0295 [MEDIUM] CVE-2010-0295: lighttpd - lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation th...
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.
Scope: local
bookworm: resolved (fixed in 1.4.26-1)
bullseye: resolved (fixed in 1.4.26-1)
forky: resolved (fixe
debian
CVE-2012-5533P4MEDIUMCVSS 5.0PoCfixed in lighttpd 1.4.31-2 (bookworm)2012
CVE-2012-5533 [MEDIUM] CVE-2012-5533: lighttpd - The http_request_split_value function in request.c in lighttpd before 1.4.32 all...
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.
Scope: local
bookworm: resolved (fixed in 1.4.31-2)
bullseye: resolved (fixed in 1.4.31-2)
forky: resol
debian
CVE-2013-4559P3HIGHCVSS 7.6fixed in lighttpd 1.4.33-1+nmu1 (bookworm)2013
CVE-2013-4559 [HIGH] CVE-2013-4559: lighttpd - lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) se...
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.
Scope: local
bookworm: r
debian
CVE-2018-19052P3HIGHCVSS 7.5fixed in lighttpd 1.4.52-1 (bookworm)2018
CVE-2018-19052 [HIGH] CVE-2018-19052: lighttpd - An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd...
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
Scope: local
bookwo
debian
CVE-2015-3200P3LOWCVSS 7.5fixed in lighttpd 1.4.37-1 (bookworm)2015
CVE-2015-3200 [HIGH] CVE-2015-3200: lighttpd - mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary l...
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.
Scope: local
bookworm: resolved (fixed in 1.4.37-1)
bullseye: resolved (fixed in 1.4.37-1)
forky: resolved (fixed in 1.4.37-1)
sid: resolved (
debian
CVE-2007-3947P4MEDIUMCVSS 5.8PoCfixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3947 [MEDIUM] CVE-2007-3947: lighttpd - request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of servic...
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.
Scope: local
bookworm: resolved (fixed in 1.4.16-1)
bullseye: resolved (fixed in 1.4.16-1)
forky: resolved (fixed
debian
CVE-2014-2324P3MEDIUMCVSS 5.0fixed in lighttpd 1.4.33-1+nmu3 (bookworm)2014
CVE-2014-2324 [MEDIUM] CVE-2014-2324: lighttpd - Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simpl...
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
Scope: local
bookworm: resolved (fixed in 1.4.33-1+nmu3)
bullseye: resolved (fixed in 1.4.33-1+nmu3)
forky: resolved (fixed in 1.4.33-
debian
CVE-2013-4508P3HIGHCVSS 7.5fixed in lighttpd 1.4.33-1+nmu1 (bookworm)2013
CVE-2013-4508 [HIGH] CVE-2013-4508: lighttpd - lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which ...
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
Scope: local
bookworm: resolved (fixed in 1.4.33-1+nmu1)
bullseye: resolved (fixed in 1.4.33-1+nmu1)
forky: resolved (fi
debian
CVE-2022-37797P3HIGHCVSS 7.5fixed in lighttpd 1.4.66-1 (bookworm)2022
CVE-2022-37797 [HIGH] CVE-2022-37797: lighttpd - In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer ...
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
Scope: local
bookworm: resolved (fixed in 1.4.66-1)
bullseye: resolved (fixed in 1.
debian
CVE-2007-3949P3HIGHCVSS 8.3fixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3949 [HIGH] CVE-2007-3949: lighttpd - mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL...
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
Scope: local
bookworm: resolved (fixed in 1.4.16-1)
bullseye: resolved (fixed in 1.4.16-1)
forky: resolved (fixed in 1.4.16-1)
sid: resolved (fixed in 1.4.16-1)
trixie: resolved (fixed in 1.4.16-1)
debian
CVE-2007-4727P3MEDIUMCVSS 6.8fixed in lighttpd 1.4.18-1 (bookworm)2007
CVE-2007-4727 [MEDIUM] CVE-2007-4727: lighttpd - Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in t...
Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPT_FILENAME variable, aka a "header overflow."
Scope: local
b
debian
CVE-2022-22707P3MEDIUMCVSS 5.9fixed in lighttpd 1.4.64-1 (bookworm)2022
CVE-2022-22707 [MEDIUM] CVE-2022-22707: lighttpd - In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the ...
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded header in a somewhat unusual manner. Also, a 3
debian
1 / 2Next →