Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via crafted base64 input that triggers an out-of-bounds read with a negative index.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lighttpd | Jul 30, 2024 | Dec 24, 2011 |
| Freebsd | — | Upgrade lighttpd | Dec 10, 2025 | Dec 28, 2011 |
| Gentoo Linux | — | Upgrade www-servers/lighttpd. | Oct 30, 2017 | Dec 24, 2011 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Dec 8, 2014 | Dec 24, 2011 |
| Oracle Solaris | — | Upgrade web/server/lighttpd-14 to version 1.4.23-0.175.0.6.0.2.0 on Solaris 11.0 | May 29, 2017 | Dec 24, 2011 |
| Suse | — | Upgrade lighttpd-mod_mysql_vhostUpgrade lighttpdUpgrade lighttpd-mod_cmlUpgrade lighttpd-mod_rrdtoolUpgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpd-mod_webdavUpgrade lighttpd-mod_magnet | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade lighttpd | Nov 19, 2024 | Dec 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub