Debian Lighttpd vulnerabilities

39 known vulnerabilities affecting debian/lighttpd.

Total CVEs
39
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM16LOW13UNKNOWN1

Vulnerabilities

Page 2 of 2
CVE-2011-3389MEDIUMCVSS 4.3PoCfixed in asterisk 1:13.7.2~dfsg-1 (bullseye)2011
CVE-2011-3389 [MEDIUM] CVE-2011-3389: asterisk - The SSL protocol, as used in certain configurations in Microsoft Windows and Mic... The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS s
debian
CVE-2011-4362LOWCVSS 5.0PoCfixed in lighttpd 1.4.30-1 (bookworm)2011
CVE-2011-4362 [MEDIUM] CVE-2011-4362: lighttpd - Integer signedness error in the base64_decode function in the HTTP authenticatio... Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via crafted base64 input that triggers an out-of-bounds read with a negative index. Scope: local bookworm: resolved (fix
debian
CVE-2010-0295MEDIUMCVSS 5.0PoCfixed in lighttpd 1.4.26-1 (bookworm)2010
CVE-2010-0295 [MEDIUM] CVE-2010-0295: lighttpd - lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation th... lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate. Scope: local bookworm: resolved (fixed in 1.4.26-1) bullseye: resolved (fixed in 1.4.26-1) forky: resolved (fixe
debian
CVE-2009-3555MEDIUMCVSS 5.8PoCfixed in apache2 2.2.14-2 (bookworm)2009
CVE-2009-3555 [MEDIUM] CVE-2009-3555: apache2 - The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Micr... The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate reneg
debian
CVE-2008-0983MEDIUMCVSS 5.0fixed in lighttpd 1.4.18-2 (bookworm)2008
CVE-2008-0983 [MEDIUM] CVE-2008-0983: lighttpd - lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly cal... lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access. Scope: local bookworm: resolved (fixed in 1.4.18-2) bullseye: resolved (fixed in 1.4.18-2) forky: res
debian
CVE-2008-1270MEDIUMCVSS 5.0PoCfixed in lighttpd 1.4.19-1 (bookworm)2008
CVE-2008-1270 [MEDIUM] CVE-2008-1270: lighttpd - mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a... mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory. Scope: local bookworm: resolved (fixed in 1.4.19-1) bullseye: resolved (fixed in 1.4.19-1) forky: resolved (fixed in 1.4.19-1) sid: resolved (fixed in 1.4.1
debian
CVE-2008-4298MEDIUMCVSS 5.0fixed in lighttpd 1.4.19-5 (bookworm)2008
CVE-2008-4298 [MEDIUM] CVE-2008-4298: lighttpd - Memory leak in the http_request_parse function in request.c in lighttpd before 1... Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers. Scope: local bookworm: resolved (fixed in 1.4.19-5) bullseye: resolved (fixed in 1.4.19-5) forky: resolved (fixed in 1.4.19-5) sid: resolved (fi
debian
CVE-2008-1111LOWCVSS 5.0fixed in lighttpd 1.4.18-4 (bookworm)2008
CVE-2008-1111 [MEDIUM] CVE-2008-1111: lighttpd - mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500... mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information. Scope: local bookworm: resolved (fixed in 1.4.18-4) bullseye: resolved (fixed in 1.4.18-4) forky: resolved (fixed in 1.4.18-4) sid: resolved (fixed in 1.4.18-4) trixie: resolved (fixed
debian
CVE-2008-4359LOWCVSS 7.5fixed in lighttpd 1.4.19-5 (bookworm)2008
CVE-2008-4359 [HIGH] CVE-2008-4359: lighttpd - lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2)... lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data. Scope: local bookworm: resolved (fixed in 1.4.19-5) bullseye: resolved (fixed in 1.4.19-
debian
CVE-2008-4360LOWCVSS 7.5fixed in lighttpd 1.4.19-5 (bookworm)2008
CVE-2008-4360 [HIGH] CVE-2008-4360: lighttpd - mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system ... mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files. Scope: loc
debian
CVE-2008-1531LOWCVSS 4.3fixed in lighttpd 1.4.19-2 (bookworm)2008
CVE-2008-1531 [MEDIUM] CVE-2008-1531: lighttpd - The connection_state_machine function (connections.c) in lighttpd 1.4.19 and ear... The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost. Scope: local bookworm: resolved (fixed in
debian
CVE-2007-3949HIGHCVSS 8.3fixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3949 [HIGH] CVE-2007-3949: lighttpd - mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL... mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings. Scope: local bookworm: resolved (fixed in 1.4.16-1) bullseye: resolved (fixed in 1.4.16-1) forky: resolved (fixed in 1.4.16-1) sid: resolved (fixed in 1.4.16-1) trixie: resolved (fixed in 1.4.16-1)
debian
CVE-2007-1869MEDIUMCVSS 5.0fixed in lighttpd 1.4.15-1 (bookworm)2007
CVE-2007-1869 [MEDIUM] CVE-2007-1869: lighttpd - lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service ... lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption. Scope: local bookworm: resolved (fixed in 1.4.15-1) bullseye: resolved (fixed in 1.4.15-1) forky: resolved (fixed in 1.4.15-1) sid:
debian
CVE-2007-3946MEDIUMCVSS 6.4fixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3946 [MEDIUM] CVE-2007-3946: lighttpd - mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to caus... mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header. Scope: local bookworm: resolved (fixed in 1.4.16-1) bullseye: resolved (fixe
debian
CVE-2007-4727MEDIUMCVSS 6.8fixed in lighttpd 1.4.18-1 (bookworm)2007
CVE-2007-4727 [MEDIUM] CVE-2007-4727: lighttpd - Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in t... Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPT_FILENAME variable, aka a "header overflow." Scope: local b
debian
CVE-2007-3950MEDIUMCVSS 4.3fixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3950 [MEDIUM] CVE-2007-3950: lighttpd - lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause ... lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules. Scope: local bookworm: resolved (fixed in 1.4.16-1) bullseye: resolved (fixed in
debian
CVE-2007-3947MEDIUMCVSS 5.8PoCfixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3947 [MEDIUM] CVE-2007-3947: lighttpd - request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of servic... request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault. Scope: local bookworm: resolved (fixed in 1.4.16-1) bullseye: resolved (fixed in 1.4.16-1) forky: resolved (fixed
debian
CVE-2007-3948LOWCVSS 4.3fixed in lighttpd 1.4.16-1 (bookworm)2007
CVE-2007-3948 [MEDIUM] CVE-2007-3948: lighttpd - connections.c in lighttpd before 1.4.16 might accept more connections than the c... connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts. Scope: local bookworm: resolved (fixed in 1.4.16-1) bullseye: resolved (fixed in 1.4.16-1) forky: resolved (fixed in 1.4.16-1) sid: resolved (fixed
debian
CVE-2007-1870LOWCVSS 7.8fixed in lighttpd 1.4.15-1 (bookworm)2007
CVE-2007-1870 [HIGH] CVE-2007-1870: lighttpd - lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via... lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 1.4.15-1) bullseye: resolved (fixed in 1.4.15-1) forky: resolved (fixed in 1.4.15-1) sid: resolved (fixed in 1.4.15-1) trixie: resolved (fixed in 1.4.15-1)
debian