Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-25103

Опубликовано: 17 июн. 2024
Источник: debian

Описание

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lighttpdfixed1.4.52-1package

Примечания

  • https://github.com/lighttpd/lighttpd1.4/commit/d161f53de04bc826ce1bdaeb3dce2c72ca50a3f8 (lighttpd-1.4.50)

  • https://github.com/lighttpd/lighttpd1.4/commit/df8e4f95614e476276a55e34da2aa8b00b1148e9 (lighttpd-1.4.51)

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.

CVSS3: 5.3
nvd
больше 1 года назад

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.

CVSS3: 5.3
github
больше 1 года назад

There exists a use-after-free-vulnerability in lighttpd <= 1.4.50 that can allow access to do a case-insensitive comparison against the reused pointer.