First published: Tue Jul 24 2007(Updated: )
lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipscms Light | <=1.4.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3950 is classified as a denial of service vulnerability.
To fix CVE-2007-3950, it is recommended to upgrade Lighttpd to a version later than 1.4.15.
Lighttpd versions up to and including 1.4.15 are affected by CVE-2007-3950.
CVE-2007-3950 involves the mod_scgi, mod_fastcgi, and mod_webdav modules.
CVE-2007-3950 enables remote attackers to cause a denial of service by crashing the Lighttpd daemon.