CVE-2007-3949: High severity Lighttpd Lighttpd vulnerability
Published Jul 24, 2007
·Updated
modaccess.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
Affected Software
1 affected component
Lighttpd Lighttpd<=1.4.15
Remediation
Patch Available
Event History
Jul 24, 2007
CVE Published
12:30 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3949?
CVE-2007-3949 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2007-3949?
To fix CVE-2007-3949, upgrade to a version of Lighttpd later than 1.4.15 which addresses this issue.
3
What does CVE-2007-3949 exploit?
CVE-2007-3949 exploits the handling of trailing slash characters in URLs by Lighttpd, allowing bypass of access controls.
4
What software is affected by CVE-2007-3949?
CVE-2007-3949 affects Lighttpd version 1.4.15 and earlier.
5
Is CVE-2007-3949 still a concern today?
While CVE-2007-3949 is an older vulnerability, it remains a concern for systems still running vulnerable versions of Lighttpd.