PT-2013-5048 · Lighttpd+1 · Lighttpd+1
Publicado
2013-11-08
·
Atualizado
2024-06-15
·
CVE-2013-4508
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
lighttpd versions 1.4.24 through 1.4.33
Description
The issue allows remote attackers to hijack sessions or obtain sensitive information by exploiting weak SSL ciphers when SNI is enabled. This can be achieved by inserting packets into the client-server data stream or sniffing the network.
Recommendations
For lighttpd versions 1.4.24 through 1.4.33, update to version 1.4.34 or later to resolve the issue.
Exploit
Correção
Inadequate Encryption Strength
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Lighttpd