Debian Lighttpd vulnerabilities
37 known vulnerabilities affecting debian/lighttpd.
Total CVEs
37
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH7MEDIUM16LOW11UNKNOWN1
Vulnerabilities
Page 2 of 2
CVE-2008-4360P3LOWCVSS 7.5fixed in lighttpd 1.4.19-5 (bookworm)2008
CVE-2008-4360 [HIGH] CVE-2008-4360: lighttpd - mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system ...
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
Scope: loc
debian
CVE-2022-41556P3HIGHCVSS 7.5fixed in lighttpd 1.4.67-1 (bookworm)2022
CVE-2022-41556 [HIGH] CVE-2022-41556: lighttpd - A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to ...
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
Scope: local
bookworm: resolved (
debian
CVE-2008-4359P3LOWCVSS 7.5fixed in lighttpd 1.4.19-5 (bookworm)2008
CVE-2008-4359 [HIGH] CVE-2008-4359: lighttpd - lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2)...
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Scope: local
bookworm: resolved (fixed in 1.4.19-5)
bullseye: resolved (fixed in 1.4.19-
debian
CVE-2018-25103P4MEDIUMCVSS 5.3fixed in lighttpd 1.4.52-1 (bookworm)2018
CVE-2018-25103 [MEDIUM] CVE-2018-25103: lighttpd - There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsin...
There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.
Scope: local
bookworm: resolved (fixed in 1.4.52-1)
bullseye: resolved (fixed in 1.4.52-1)
forky: resolved (fixed in 1.4.52-1)
sid: resolved (fixed in 1.4.52-1)
trixie: resolved (fixe
debian
CVE-2013-4560P4MEDIUMCVSS 5.0fixed in lighttpd 1.4.33-1+nmu1 (bookworm)2013
CVE-2013-4560 [MEDIUM] CVE-2013-4560: lighttpd - Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers t...
Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.
Scope: local
bookworm: resolved (fixed in 1.4.33-1+nmu1)
bullseye: resolved (fixed in 1.4.33-1+nmu1)
forky: resolved (fixed in 1.4.33-1+nmu1)
sid: resolved (fixe
debian
CVE-2007-1870P4LOWCVSS 7.8fixed in lighttpd 1.4.15-1 (bookworm)2007
CVE-2007-1870 [HIGH] CVE-2007-1870: lighttpd - lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via...
lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 1.4.15-1)
bullseye: resolved (fixed in 1.4.15-1)
forky: resolved (fixed in 1.4.15-1)
sid: resolved (fixed in 1.4.15-1)
trixie: resolved (fixed in 1.4.15-1)
debian
CVE-2007-3946P4MEDIUMCVSS 6.4fixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3946 [MEDIUM] CVE-2007-3946: lighttpd - mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to caus...
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.
Scope: local
bookworm: resolved (fixed in 1.4.16-1)
bullseye: resolved (fixe
debian
CVE-2008-4298P4MEDIUMCVSS 5.0fixed in lighttpd 1.4.19-5 (bookworm)2008
CVE-2008-4298 [MEDIUM] CVE-2008-4298: lighttpd - Memory leak in the http_request_parse function in request.c in lighttpd before 1...
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
Scope: local
bookworm: resolved (fixed in 1.4.19-5)
bullseye: resolved (fixed in 1.4.19-5)
forky: resolved (fixed in 1.4.19-5)
sid: resolved (fi
debian
CVE-2007-1869P4MEDIUMCVSS 5.0fixed in lighttpd 1.4.15-1 (bookworm)2007
CVE-2007-1869 [MEDIUM] CVE-2007-1869: lighttpd - lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service ...
lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.
Scope: local
bookworm: resolved (fixed in 1.4.15-1)
bullseye: resolved (fixed in 1.4.15-1)
forky: resolved (fixed in 1.4.15-1)
sid:
debian
CVE-2008-0983P4MEDIUMCVSS 5.0fixed in lighttpd 1.4.18-2 (bookworm)2008
CVE-2008-0983 [MEDIUM] CVE-2008-0983: lighttpd - lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly cal...
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
Scope: local
bookworm: resolved (fixed in 1.4.18-2)
bullseye: resolved (fixed in 1.4.18-2)
forky: res
debian
CVE-2008-1531P4LOWCVSS 4.3fixed in lighttpd 1.4.19-2 (bookworm)2008
CVE-2008-1531 [MEDIUM] CVE-2008-1531: lighttpd - The connection_state_machine function (connections.c) in lighttpd 1.4.19 and ear...
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2008-1111P4LOWCVSS 5.0fixed in lighttpd 1.4.18-4 (bookworm)2008
CVE-2008-1111 [MEDIUM] CVE-2008-1111: lighttpd - mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500...
mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.
Scope: local
bookworm: resolved (fixed in 1.4.18-4)
bullseye: resolved (fixed in 1.4.18-4)
forky: resolved (fixed in 1.4.18-4)
sid: resolved (fixed in 1.4.18-4)
trixie: resolved (fixed
debian
CVE-2007-3950P4MEDIUMCVSS 4.3fixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3950 [MEDIUM] CVE-2007-3950: lighttpd - lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause ...
lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules.
Scope: local
bookworm: resolved (fixed in 1.4.16-1)
bullseye: resolved (fixed in
debian
CVE-2007-3948P4LOWCVSS 4.3fixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3948 [MEDIUM] CVE-2007-3948: lighttpd - connections.c in lighttpd before 1.4.16 might accept more connections than the c...
connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts.
Scope: local
bookworm: resolved (fixed in 1.4.16-1)
bullseye: resolved (fixed in 1.4.16-1)
forky: resolved (fixed in 1.4.16-1)
sid: resolved (fixed
debian
CVE-2012-4929P4LOWCVSS 2.6fixed in apache2 2.2.22-12 (bookworm)2012
CVE-2012-4929 [LOW] CVE-2012-4929: apache2 - The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt,...
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potenti
debian
CVE-2013-1427P4LOWCVSS 1.9fixed in lighttpd 1.4.31-4 (bookworm)2013
CVE-2013-1427 [LOW] CVE-2013-1427: lighttpd - The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on...
The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.
Scope: local
bookworm: resolve
debian
CVE-2016-1000212UNKNOWNfixed in lighttpd 1.4.43-1 (bookworm)2016
CVE-2016-1000212 CVE-2016-1000212: lighttpd
bookworm: resolved (fixed in 1.4.43-1)
bullseye: resolved (fixed in 1.4.43-1)
forky: resolved (fixed in 1.4.43-1)
sid: resolved (fixed in 1.4.43-1)
trixie: resolved (fixed in 1.4.43-1)
debian
← Previous2 / 2