USN-4775-1
Dashboard / Vulnerabilities / USN-4775-1
USN-4775-1
Summary: lighttpd vulnerabilities
Details: It was discovered that Lighttpd did not properly sanitized the string used in basic HTTP authentication method. A remote attacker could use this to inject arbitrary log entries and maybe obtain sensitive information. This issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2015-3200) It was discovered that Lighttpd did not properly sanitized the string used in alias. A remote attacker could use this to access the content of the directory above the alias and obtain sensitive information. (CVE-2018-19052)
References: https://ubuntu.com/security/notices/USN-4775-1, https://ubuntu.com/security/CVE-2015-3200, https://ubuntu.com/security/CVE-2018-19052
Affected packages
Package
Name: lighttpd
Purl: pkg:deb/ubuntu/lighttpd?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
