CVE-2013-4508: Weak Encryption
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4508?
CVE-2013-4508 is considered a medium severity vulnerability due to weak SSL ciphers that can lead to session hijacking and sensitive information exposure.
How do I fix CVE-2013-4508?
To fix CVE-2013-4508, upgrade lighttpd to version 1.4.34 or later, ensuring that strong SSL ciphers are configured.
Which versions of lighttpd are affected by CVE-2013-4508?
Versions of lighttpd prior to 1.4.34, specifically 1.4.24 to 1.4.33, are affected by CVE-2013-4508.
What impact does CVE-2013-4508 have on users?
CVE-2013-4508 can allow remote attackers to hijack sessions and capture sensitive information by exploiting weak SSL ciphers.
On which operating systems can CVE-2013-4508 be found?
CVE-2013-4508 affects lighttpd running on various versions of Debian and openSUSE.