5
CVSSv2

CVE-2008-1111

Published: 04/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote malicious users to obtain sensitive information.

Vulnerable Product Search on Vulmon Subscribe to Product

lighttpd lighttpd 1.4.18

Vendor Advisories

Debian Bug report logs - #469307 lighttpd: CVE-2008-1111 reveals cgi source if the cgi handler fork fails Package: lighttpd; Maintainer for lighttpd is Debian QA Group <packages@qadebianorg>; Source for lighttpd is src:lighttpd (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Tue, 4 Mar 2008 1 ...
It was discovered that lighttpd, a fast webserver with minimal memory footprint, would display the source to CGI scripts if their execution failed in some circumstances For the stable distribution (etch), this problem has been fixed in version 1413-4etch5 For the unstable distribution, this problem will be fixed soon We recommend that you upgr ...