CVE-2018-25103

EUVD-2018-21592
There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
lighttpdlighttpd
𝑥
≤ 1.4.50
ADP
Debian logo
Debian Releases
Debian Product
Codename
lighttpd
bookworm
1.4.69-1
fixed
bullseye
1.4.59-1+deb11u2
fixed
bullseye (security)
1.4.59-1+deb11u2
fixed
sid
1.4.76-1
fixed
trixie
1.4.76-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lighttpd
bionic
needs-triage
focal
not-affected
jammy
not-affected
mantic
not-affected
noble
not-affected
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
lighttpd
Amazon Linux 1
0:1.4.53-1.36.amzn1
fixed
lighttpd-debuginfo
Amazon Linux 1
0:1.4.53-1.36.amzn1
fixed
lighttpd-fastcgi
Amazon Linux 1
0:1.4.53-1.36.amzn1
fixed
lighttpd-mod_authn_gssapi
Amazon Linux 1
0:1.4.53-1.36.amzn1
fixed
lighttpd-mod_authn_mysql
Amazon Linux 1
0:1.4.53-1.36.amzn1
fixed
lighttpd-mod_authn_pam
Amazon Linux 1
0:1.4.53-1.36.amzn1
fixed
lighttpd-mod_geoip
Amazon Linux 1
0:1.4.53-1.36.amzn1
fixed
lighttpd-mod_mysql_vhost
Amazon Linux 1
0:1.4.53-1.36.amzn1
fixed