CVE-2008-4359
Summary
| CVE | CVE-2008-4359 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-03 17:41:40 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 4.0 | All | All | All |
| Application | Lighttpd | Lighttpd | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.lighttpd.net/security/lighttpd-1.4.x_rewrite_redirect_decode_url.patch | af854a3a-2127-422b-91ae-364da2661108 | www.lighttpd.net | Patch, Vendor Advisory |
| rPath update for lighttpd - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| www.lighttpd.net/security/lighttpd_sa_2008_05.txt | af854a3a-2127-422b-91ae-364da2661108 | www.lighttpd.net | Vendor Advisory |
| Security Advisory SA32972 - Gentoo update for lighttpd - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Changeset 2307 – lighttpd – Trac | af854a3a-2127-422b-91ae-364da2661108 | trac.lighttpd.net | Broken Link, Vendor Advisory |
| Lighttpd - Bug #1720: Rewrite/redirect rules and URL encoding - lighty labs | af854a3a-2127-422b-91ae-364da2661108 | trac.lighttpd.net | Vendor Advisory |
| SUSE update for phpMyAdmin and lighttpd - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Advisories:rPSA-2008-0309 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | Third Party Advisory |
| oss-security - Re: Re: CVE request: lighttpd issues | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List |
| Lighttpd URI Rewrite/Redirect Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1645-1 lighttpd | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| lighttpd: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Changeset 2278 – lighttpd – Trac | af854a3a-2127-422b-91ae-364da2661108 | trac.lighttpd.net | Broken Link, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| oss-security - Re: CVE request: lighttpd issues | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List |
| Advisories:rPSA-2008-0309 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | Third Party Advisory |
| Debian update for lighttpd - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| lighttpd Weakness and Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| oss-security - Re: CVE request: lighttpd issues | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Changeset 2309 – lighttpd – Trac | af854a3a-2127-422b-91ae-364da2661108 | trac.lighttpd.net | Broken Link, Vendor Advisory |
| Changeset 2310 – lighttpd – Trac | af854a3a-2127-422b-91ae-364da2661108 | trac.lighttpd.net | Broken Link, Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2008:026 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.