PT-2024-10621 · Lighttpd · Lighttpd

Ori Hollander

·

Published

2024-06-17

·

Updated

2024-07-09

·

CVE-2018-25103

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions lighttpd versions <= 1.4.50
Description The issue is related to a use-after-free vulnerability that can allow access to compare data in a case-insensitive manner with a reused pointer. This vulnerability might read from invalid pointers to memory used in the same request.
Recommendations For lighttpd versions <= 1.4.50, update to a version greater than 1.4.50 to resolve the issue. At the moment, there is no information about other specific workarounds for this vulnerability.

Fix

Related Identifiers

CVE-2018-25103

Affected Products

Lighttpd