Lighttpd Multiple Code Execution, Denial of Service and Information Disclosure Vulnerabilities
BID:24967
Info
Lighttpd Multiple Code Execution, Denial of Service and Information Disclosure Vulnerabilities
| Bugtraq ID: | 24967 |
| Class: | Unknown |
| CVE: |
CVE-2007-3946 CVE-2007-3947 CVE-2007-3948 CVE-2007-3949 CVE-2007-3950 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2007 12:00AM |
| Updated: | Jul 15 2008 11:09PM |
| Credit: | Jeff Uphoff, Jonathan Smith and Joseph Tate are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. openSUSE 10.2 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 lighttpd lighttpd 1.4.15 lighttpd lighttpd 1.4.14 lighttpd lighttpd 1.4.13 lighttpd lighttpd 1.4.12 lighttpd lighttpd 1.4.11 lighttpd lighttpd 1.4.10 lighttpd lighttpd 1.4.9 lighttpd lighttpd 1.4.8 lighttpd lighttpd 1.4.7 lighttpd lighttpd 1.4.6 lighttpd lighttpd 1.4.5 lighttpd lighttpd 1.4.4 lighttpd lighttpd 1.4.3 lighttpd lighttpd 1.4.2 lighttpd lighttpd 1.4.1 lighttpd lighttpd 1.4 lighttpd lighttpd 1.4.10a Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
lighttpd lighttpd 1.4.16 |
Discussion
Lighttpd Multiple Code Execution, Denial of Service and Information Disclosure Vulnerabilities
Lighttpd is prone to multiple remote denial-of-service vulnerabilities, a code-execution vulnerability, and an information-disclosure vulnerability.
An attacker can exploit these issues to execute arbitrary code, access sensitive information, or crash the affected application, denying service to legitimate users.
These issues affect versions prior to lighttpd 1.4.16.
Lighttpd is prone to multiple remote denial-of-service vulnerabilities, a code-execution vulnerability, and an information-disclosure vulnerability.
An attacker can exploit these issues to execute arbitrary code, access sensitive information, or crash the affected application, denying service to legitimate users.
These issues affect versions prior to lighttpd 1.4.16.
Exploit / POC
Lighttpd Multiple Code Execution, Denial of Service and Information Disclosure Vulnerabilities
An attacker can exploit these issues through a browser.
The following Metasploit exploit module is available:
An attacker can exploit these issues through a browser.
The following Metasploit exploit module is available:
Solution / Fix
Lighttpd Multiple Code Execution, Denial of Service and Information Disclosure Vulnerabilities
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Debian Linux 4.0 arm
Debian Linux 4.0 powerpc
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 4.0 alpha
Debian Linux 4.0 mipsel
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Debian Linux 4.0 arm
-
Debian lighttpd-mod-cml_1.4.13-4etch3_arm.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-c ml_1.4.13-4etch3_arm.deb
Debian Linux 4.0 powerpc
-
Debian lighttpd-mod-mysql-vhost_1.4.13-4etch3_powerpc.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m ysql-vhost_1.4.13-4etch3_powerpc.deb
Debian Linux 4.0 amd64
-
Debian lighttpd-mod-trigger-b4-dl_1.4.13-4etch3_amd64.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-t rigger-b4-dl_1.4.13-4etch3_amd64.deb
Debian Linux 4.0 ia-32
-
Debian lighttpd-mod-trigger-b4-dl_1.4.13-4etch3_i386.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-t rigger-b4-dl_1.4.13-4etch3_i386.deb
Debian Linux 4.0 hppa
-
Debian lighttpd-mod-webdav_1.4.13-4etch3_hppa.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-w ebdav_1.4.13-4etch3_hppa.deb
Debian Linux 4.0 sparc
-
Debian lighttpd-mod-trigger-b4-dl_1.4.13-4etch3_sparc.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-t rigger-b4-dl_1.4.13-4etch3_sparc.deb
Debian Linux 4.0 s/390
-
Debian lighttpd-mod-webdav_1.4.13-4etch3_s390.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-w ebdav_1.4.13-4etch3_s390.deb
Debian Linux 4.0 alpha
-
Debian lighttpd-mod-webdav_1.4.13-4etch3_alpha.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-w ebdav_1.4.13-4etch3_alpha.deb
Debian Linux 4.0 mipsel
-
Debian lighttpd-mod-webdav_1.4.13-4etch3_mipsel.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-w ebdav_1.4.13-4etch3_mipsel.deb
Debian Linux 4.0 ia-64
-
Debian lighttpd-mod-mysql-vhost_1.4.13-4etch3_ia64.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m ysql-vhost_1.4.13-4etch3_ia64.deb
Debian Linux 4.0 mips
-
Debian lighttpd-mod-mysql-vhost_1.4.13-4etch3_mips.deb
http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m ysql-vhost_1.4.13-4etch3_mips.deb
References
Lighttpd Multiple Code Execution, Denial of Service and Information Disclosure Vulnerabilities
References:
References:
- [framework] Lighttpd header folding exploit (Abhisek Datta)
- lighttpd Home Page (lighttpd)
- lighttpd patch available to fix a seg fault (rPath )
- lighttpd-1.4.15: multiple DoS vulnerabilities; information disclosure CVE-unknow (rPath)