First published: Fri Oct 03 2008(Updated: )
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipscms Light | <1.4.20 | |
Debian | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4359 has a moderate severity level due to the potential for unauthorized access to sensitive information.
To fix CVE-2008-4359, update lighttpd to version 1.4.20 or later, which addresses the vulnerability.
CVE-2008-4359 can allow remote attackers to bypass access restrictions, potentially exposing sensitive data or allowing data modification.
CVE-2008-4359 affects lighttpd versions prior to 1.4.20 and specific versions of Debian Linux 4.0.
Temporary workarounds for CVE-2008-4359 include disabling URL redirection or rewriting until an update can be applied.