mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lighttpd | Jul 30, 2024 | Mar 4, 2008 |
| Gentoo Linux | — | Upgrade www-servers/lighttpd. | Oct 30, 2017 | Mar 4, 2008 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Dec 8, 2014 | Mar 4, 2008 |
| Suse | — | Upgrade lighttpd-mod_rrdtoolUpgrade lighttpd-mod_mysql_vhostUpgrade lighttpdUpgrade lighttpd-mod_cmlUpgrade lighttpd-mod_magnetUpgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpd-mod_webdav | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade lighttpd | Nov 19, 2024 | Mar 4, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub