REDHAT-BUG-758624: Medium severity Lighttpd Lighttpd vulnerability
An signedness error, leading to out of stack-based buffer read flaw was found in the way lighttpd, a lightning fast webserver with light system requirements, processed certain invalid base64 HTTP authentication tokens. A remote attacker could provide a specially crafted HTTP authentication request, leading to denial of service (lighttpd daemon crash due to an signedness error while processing the token).
Upstream bug report: [1] http://redmine.lighttpd.net/issues/2370
Upstream patch (with testcase and NEWS update): [2] http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2806/diff
References: [3] http://download.lighttpd.net/lighttpd/security/lighttpdsa201101.txt (upstream advisory) [4] http://www.openwall.com/lists/oss-security/2011/11/29/8 (CVE request) [5] http://www.openwall.com/lists/oss-security/2011/11/29/13 (CVE assignment)
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-758624?
The severity of REDHAT-BUG-758624 is considered high due to the potential for remote code execution via specially crafted HTTP authentication requests.
How do I fix REDHAT-BUG-758624?
To fix REDHAT-BUG-758624, you should upgrade to the latest version of lighttpd that addresses the signedness error.
What systems are affected by REDHAT-BUG-758624?
The systems affected by REDHAT-BUG-758624 include those running the lighttpd web server that process HTTP authentication requests.
What type of vulnerability is REDHAT-BUG-758624?
REDHAT-BUG-758624 is classified as an out-of-bounds read vulnerability due to a signedness error in processing base64 HTTP authentication tokens.
Can REDHAT-BUG-758624 be exploited remotely?
Yes, REDHAT-BUG-758624 can be exploited remotely by an attacker sending a specially crafted HTTP authentication request.