First published: Mon Jun 17 2024(Updated: )
There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipscms Light | <=1.4.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-25103 is classified as a moderate severity vulnerability due to the potential for memory corruption and exploitation.
To fix CVE-2018-25103, upgrade lighttpd to version 1.4.51 or later, which addresses the use-after-free vulnerabilities.
CVE-2018-25103 affects lighttpd versions up to and including 1.4.50, commonly used in web server deployments.
CVE-2018-25103 involves use-after-free vulnerabilities in the request parsing process, potentially allowing reading from invalid memory pointers.
Yes, CVE-2018-25103 can be exploited remotely if an attacker can send crafted requests to the vulnerable lighttpd server.