Cryptographic issues in lighttpd - CVE-2013-4508
Published: November 8, 2013 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network. Per: http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_01.txt "All versions from 1.4.24 (first version supporting SNI) up to and including 1.4.33."
Affected software
Gentoo Linux
Amazon Linux AMI
Fedora
lighttpd (Alpine package)
lighttpd
Adobe Commerce (formerly Magento Commerce)
Virtual Customer Access System (vCAS)
How to mitigate CVE-2013-4508
lighttpd (Alpine package) - update to 1.4.33-r1
lighttpd - addressed in versions 1.4.34-1.el5.1, 1.4.34-1.el6
Virtual Customer Access System (vCAS) - update to 14.10-38402
External References
- http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_01.txt
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00049.html
- http://marc.info/?l=bugtraq&m=141576815022399&w=2
- http://openwall.com/lists/oss-security/2013/11/04/19
- http://redmine.lighttpd.net/issues/2525
- http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2913/diff/
- https://www.debian.org/security/2013/dsa-2795
Related Security Bulletins
- Cryptographic issues in lighttpd
- Cryptographic issues in lighttpd (Alpine package)
- Amazon Linux AMI update for lighttpd
- Gentoo update for lighttpd
- Multiple vulnerabilities in HP Remote Device Access: Virtual Customer Access System (vCAS)
- Fedora EPEL 6 update for lighttpd
- Fedora EPEL 5 update for lighttpd