PT-2007-5168 · Lighttpd · Lighttpd

Publicado

2007-07-23

·

Atualizado

2018-10-15

·

CVE-2007-3948

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: lighttpd versions 1.4.15 and prior
Description: The issue allows remote attackers to cause a denial of service or access restricted files. Errors exist in the processing of HTTP headers, mod auth, and the mechanism that limits the number of active connections. Additionally, issues are present in mod scgi, the return value of base64 decode in mod auth, and the header parsing code, which can lead to memory corruption.
Recommendations: For lighttpd versions 1.4.15 and prior, update to version 1.4.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable mod auth and mod scgi modules until a patch is available. Avoid using the base64 decode function in mod auth for basic authentication until the issue is resolved. Restrict the number of active connections to prevent denial of service attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3948

Produtos afetados

Lighttpd