lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
References
Configurations
History
21 Nov 2024, 00:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html - Third Party Advisory | |
References | () http://openwall.com/lists/oss-security/2008/09/30/1 - Mailing List | |
References | () http://openwall.com/lists/oss-security/2008/09/30/2 - Mailing List | |
References | () http://openwall.com/lists/oss-security/2008/09/30/3 - Mailing List | |
References | () http://secunia.com/advisories/32069 - Third Party Advisory | |
References | () http://secunia.com/advisories/32132 - Third Party Advisory | |
References | () http://secunia.com/advisories/32480 - Third Party Advisory | |
References | () http://secunia.com/advisories/32834 - Third Party Advisory | |
References | () http://secunia.com/advisories/32972 - Third Party Advisory | |
References | () http://security.gentoo.org/glsa/glsa-200812-04.xml - Third Party Advisory | |
References | () http://trac.lighttpd.net/trac/changeset/2278 - Broken Link, Vendor Advisory | |
References | () http://trac.lighttpd.net/trac/changeset/2307 - Broken Link, Vendor Advisory | |
References | () http://trac.lighttpd.net/trac/changeset/2309 - Broken Link, Vendor Advisory | |
References | () http://trac.lighttpd.net/trac/changeset/2310 - Broken Link, Vendor Advisory | |
References | () http://trac.lighttpd.net/trac/ticket/1720 - Vendor Advisory | |
References | () http://wiki.rpath.com/Advisories:rPSA-2008-0309 - Third Party Advisory | |
References | () http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309 - Third Party Advisory | |
References | () http://www.debian.org/security/2008/dsa-1645 - Third Party Advisory | |
References | () http://www.lighttpd.net/security/lighttpd-1.4.x_rewrite_redirect_decode_url.patch - Patch, Vendor Advisory | |
References | () http://www.lighttpd.net/security/lighttpd_sa_2008_05.txt - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/497932/100/0/threaded - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/31599 - Third Party Advisory, VDB Entry | |
References | () http://www.vupen.com/english/advisories/2008/2741 - Third Party Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/45690 - Third Party Advisory, VDB Entry |
Information
Published : 2008-10-03 17:41
Updated : 2024-11-21 00:51
NVD link : CVE-2008-4359
Mitre link : CVE-2008-4359
CVE.ORG link : CVE-2008-4359
JSON object : View
Products Affected
debian
- debian_linux
lighttpd
- lighttpd
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor