CVE-2008-4359: Infoleak
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4359?
CVE-2008-4359 has a moderate severity level due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2008-4359?
To fix CVE-2008-4359, update lighttpd to version 1.4.20 or later, which addresses the vulnerability.
What types of attacks are possible with CVE-2008-4359?
CVE-2008-4359 can allow remote attackers to bypass access restrictions, potentially exposing sensitive data or allowing data modification.
Which software versions are affected by CVE-2008-4359?
CVE-2008-4359 affects lighttpd versions prior to 1.4.20 and specific versions of Debian Linux 4.0.
Are there any workarounds for CVE-2008-4359?
Temporary workarounds for CVE-2008-4359 include disabling URL redirection or rewriting until an update can be applied.