Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPT_FILENAME variable, aka a "header overflow."
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lighttpd | Jul 30, 2024 | Sep 12, 2007 |
| Freebsd | — | Upgrade lighttpd | Dec 10, 2025 | Sep 10, 2007 |
| Gentoo Linux | — | Upgrade www-servers/lighttpd.Upgrade dev-lang/php. | Oct 30, 2017 | Sep 12, 2007 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Dec 8, 2014 | Sep 12, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpd-mod_magnetUpgrade lighttpdUpgrade lighttpd-mod_webdavUpgrade lighttpd-mod_rrdtoolUpgrade lighttpd-mod_mysql_vhostUpgrade lighttpd-mod_cml | Feb 17, 2015 | Sep 12, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub