All errata/p7/ALT-PU-2015-1648-1
ALT-PU-2015-1648-1

Package update lighttpd in branch p7

Version1.4.36-alt0.M70P.1
Published2015-08-02
Max severityHIGH
Severity:

Closed issues (1)

CVE-2015-3200
HIGH7.5

mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.

Published: 2015-06-09Modified: 2025-04-12
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N