Executive Summary
Summary | |
---|---|
Title | New lighttpd packages fix CGI source disclosure |
Informations | |||
---|---|---|---|
Name | DSA-1513 | First vendor Publication | 2008-03-06 |
Vendor | Debian | Last vendor Modification | 2008-03-06 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
It was discovered that lighttpd, a fast webserver with minimal memory footprint, would display the source to CGI scripts if their execution failed in some circumstances. For the stable distribution (etch), this problem has been fixed in version 1.4.13-4etch5. For the unstable distribution, this problem will be fixed soon. We recommend that you upgrade your lighttpd package. |
Original Source
Url : http://www.debian.org/security/2008/dsa-1513 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-200 | Information Exposure |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20397 | |||
Oval ID: | oval:org.mitre.oval:def:20397 | ||
Title: | DSA-1513-1 lighttpd - information disclosure | ||
Description: | It was discovered that lighttpd, a fast webserver with minimal memory footprint, would display the source to CGI scripts if their execution failed in some circumstances. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1513-1 CVE-2008-1111 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | lighttpd |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:7977 | |||
Oval ID: | oval:org.mitre.oval:def:7977 | ||
Title: | DSA-1513 lighttpd -- information disclosure | ||
Description: | It was discovered that lighttpd, a fast webserver with minimal memory footprint, would display the source to CGI scripts if their execution failed in some circumstances. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1513 CVE-2008-1111 | Version: | 3 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | lighttpd |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2009-02-17 | Name : Fedora Update for lighttpd FEDORA-2008-3343 File : nvt/gb_fedora_2008_3343_lighttpd_fc7.nasl |
2009-02-17 | Name : Fedora Update for lighttpd FEDORA-2008-3376 File : nvt/gb_fedora_2008_3376_lighttpd_fc8.nasl |
2009-02-16 | Name : Fedora Update for lighttpd FEDORA-2008-2262 File : nvt/gb_fedora_2008_2262_lighttpd_fc7.nasl |
2009-02-16 | Name : Fedora Update for lighttpd FEDORA-2008-2278 File : nvt/gb_fedora_2008_2278_lighttpd_fc8.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200803-10 (lighttpd) File : nvt/glsa_200803_10.nasl |
2008-03-11 | Name : Debian Security Advisory DSA 1513-1 (lighttpd) File : nvt/deb_1513_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
43169 | lighttpd mod_cgi Fork Failure CGI Source Disclosure |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-02-06 | Name : The remote web server is affected by multiple vulnerabilities File : lighttpd_1_4_19.nasl - Type : ACT_GATHER_INFO |
2008-04-04 | Name : The remote openSUSE host is missing a security update. File : suse_lighttpd-5107.nasl - Type : ACT_GATHER_INFO |
2008-03-07 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1513.nasl - Type : ACT_GATHER_INFO |
2008-03-07 | Name : The remote Fedora host is missing a security update. File : fedora_2008-2262.nasl - Type : ACT_GATHER_INFO |
2008-03-07 | Name : The remote Fedora host is missing a security update. File : fedora_2008-2278.nasl - Type : ACT_GATHER_INFO |
2008-03-07 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200803-10.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:27:24 |
|