[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2012-107 --- lighttpd

ID: oval:org.secpod.oval:def:1601279Date: (C)2020-11-27   (M)2022-11-29
Class: PATCHFamily: unix




Integer signedness error in the base64_decode function in the HTTP authentication functionality in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service via crafted base64 input that triggers an out-of-bounds read with a negative index.

Platform:
Amazon Linux AMI
Product:
lighttpd
Reference:
ALAS-2012-107
CVE-2011-4362
CVE    1
CVE-2011-4362
CPE    27
cpe:/o:amazon:linux
cpe:/a:lighttpd:lighttpd:1.3.16
cpe:/a:lighttpd:lighttpd
cpe:/a:lighttpd:lighttpd:1.4.25
...

© SecPod Technologies