PT-2024-10621 · Lighttpd · Lighttpd
Ori Hollander
·
Published
2024-06-17
·
Updated
2024-07-09
·
CVE-2018-25103
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
lighttpd versions <= 1.4.50
Description
The issue is related to a use-after-free vulnerability that can allow access to compare data in a case-insensitive manner with a reused pointer. This vulnerability might read from invalid pointers to memory used in the same request.
Recommendations
For lighttpd versions <= 1.4.50, update to a version greater than 1.4.50 to resolve the issue.
At the moment, there is no information about other specific workarounds for this vulnerability.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lighttpd