Vulnerability Description
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lighttpd | Lighttpd | >= 1.4.24, <= 1.4.33 |
| Debian | Debian Linux | 6.0 |
| Opensuse | Opensuse | 12.2 |
Related Weaknesses (CWE)
References
- http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_01.txtExploitMitigationVendor Advisory
- http://jvn.jp/en/jp/JVN37417423/index.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00049.htmlMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=141576815022399&w=2Issue TrackingThird Party Advisory
- http://openwall.com/lists/oss-security/2013/11/04/19Mailing ListThird Party Advisory
- http://redmine.lighttpd.net/issues/2525Issue TrackingVendor Advisory
- http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2913/diff/Broken Link
- https://www.debian.org/security/2013/dsa-2795Third Party Advisory
- http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_01.txtExploitMitigationVendor Advisory
- http://jvn.jp/en/jp/JVN37417423/index.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00049.htmlMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=141576815022399&w=2Issue TrackingThird Party Advisory
- http://openwall.com/lists/oss-security/2013/11/04/19Mailing ListThird Party Advisory
- http://redmine.lighttpd.net/issues/2525Issue TrackingVendor Advisory
- http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2913/diff/Broken Link
FAQ
What is CVE-2013-4508?
CVE-2013-4508 is a vulnerability with a CVSS score of 7.5 (HIGH). lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtai...
How severe is CVE-2013-4508?
CVE-2013-4508 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4508?
Check the references section above for vendor advisories and patch information. Affected products include: Lighttpd Lighttpd, Debian Debian Linux, Opensuse Opensuse.