Lighttpd 'mod_cgi' Information Disclosure Vulnerability
BID:28100
Info
Lighttpd 'mod_cgi' Information Disclosure Vulnerability
| Bugtraq ID: | 28100 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1111 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2008 12:00AM |
| Updated: | Apr 08 2008 01:38AM |
| Credit: | Johan Bergström reported this issue as a Gentoo bug. |
| Vulnerable: |
SuSE SUSE Linux Enterprise SDK 10 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc rPath rPath Linux 1 Red Hat Fedora 8 Red Hat Fedora 7 lighttpd lighttpd 1.4.18 lighttpd lighttpd 1.4.17 lighttpd lighttpd 1.4.16 lighttpd lighttpd 1.4.15 lighttpd lighttpd 1.4.14 lighttpd lighttpd 1.4.13 lighttpd lighttpd 1.4.12 lighttpd lighttpd 1.4.11 lighttpd lighttpd 1.4.10 lighttpd lighttpd 1.4.9 lighttpd lighttpd 1.4.8 lighttpd lighttpd 1.4.7 lighttpd lighttpd 1.4.6 lighttpd lighttpd 1.4.5 lighttpd lighttpd 1.4.4 lighttpd lighttpd 1.4.3 lighttpd lighttpd 1.4.2 lighttpd lighttpd 1.4.1 lighttpd lighttpd 1.4 lighttpd lighttpd 1.4.10a Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Lighttpd 'mod_cgi' Information Disclosure Vulnerability
The 'lighttpd' program is prone to a vulnerability that in certain circumstances may allow attackers to access source code because the application fails to properly handle exceptional conditions.
Attackers can exploit this vulnerability to obtain potentially sensitive information that may aid in further attacks.
This issue affects lighttpd 1.4.18; other versions may also be vulnerable.
The 'lighttpd' program is prone to a vulnerability that in certain circumstances may allow attackers to access source code because the application fails to properly handle exceptional conditions.
Attackers can exploit this vulnerability to obtain potentially sensitive information that may aid in further attacks.
This issue affects lighttpd 1.4.18; other versions may also be vulnerable.
Exploit / POC
Lighttpd 'mod_cgi' Information Disclosure Vulnerability
To exploit this vulnerability, attackers can use a browser and other standard tools.
To exploit this vulnerability, attackers can use a browser and other standard tools.
Solution / Fix
Lighttpd 'mod_cgi' Information Disclosure Vulnerability
Solution:
Fixes are available in the SVN repository. Please see the references for more information.
Solution:
Fixes are available in the SVN repository. Please see the references for more information.
References
Lighttpd 'mod_cgi' Information Disclosure Vulnerability
References:
References:
- Bug#: 211956 www-servers/lighttpd <1.4.18-r2 mod_cgi vulnerability (CVE-2008-111 (Gentoo)
- Lighttpd Changeset 2107 (Lighttpd)
- lighttpd Home Page (lighttpd)