lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2013-11-08 04:47
Updated : 2025-04-11 00:51
NVD link : CVE-2013-4508
Mitre link : CVE-2013-4508
CVE.ORG link : CVE-2013-4508
JSON object : View
Products Affected
opensuse
- opensuse
lighttpd
- lighttpd
debian
- debian_linux
CWE
CWE-326
Inadequate Encryption Strength