CVE-2013-4508
08.11.2013, 04:47
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.Enginsight
Vendor | Product | Version |
---|---|---|
lighttpd | lighttpd | 1.4.24 ≤ 𝑥 ≤ 1.4.33 |
debian | debian_linux | 6.0 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
opensuse | opensuse | 12.2 |
opensuse | opensuse | 12.3 |
opensuse | opensuse | 13.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References