PT-2013-5048 · Lighttpd+1 · Lighttpd+1
Published
2013-11-08
·
Updated
2024-06-15
·
CVE-2013-4508
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
lighttpd versions 1.4.24 through 1.4.33
Description
The issue allows remote attackers to hijack sessions or obtain sensitive information by exploiting weak SSL ciphers when SNI is enabled. This can be achieved by inserting packets into the client-server data stream or sniffing the network.
Recommendations
For lighttpd versions 1.4.24 through 1.4.33, update to version 1.4.34 or later to resolve the issue.
Exploit
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Lighttpd