CVE
- Id
- 31228
- CVE No.
- CVE-2008-1111
- Status
- Candidate
- Description
- mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.
- Phase
- Assigned (20080302)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
333345 | 31228 | CVE-2008-1111 | BUGTRAQ:20080312 rPSA-2008-0106-1 lighttpd | View |
333346 | 31228 | CVE-2008-1111 | URL:http://www.securityfocus.com/archive/1/archive/1/489465/100/0/threaded | View |
333347 | 31228 | CVE-2008-1111 | MISC:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0106 | View |
333348 | 31228 | CVE-2008-1111 | MISC:https://issues.rpath.com/browse/RPL-2326 | View |
333349 | 31228 | CVE-2008-1111 | CONFIRM:http://trac.lighttpd.net/trac/changeset/2107 | View |
333350 | 31228 | CVE-2008-1111 | CONFIRM:https://bugs.gentoo.org/show_bug.cgi?id=211956 | View |
333351 | 31228 | CVE-2008-1111 | DEBIAN:DSA-1513 | View |
333352 | 31228 | CVE-2008-1111 | URL:http://www.debian.org/security/2008/dsa-1513 | View |
333353 | 31228 | CVE-2008-1111 | FEDORA:FEDORA-2008-2262 | View |
333354 | 31228 | CVE-2008-1111 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00162.html | View |
333355 | 31228 | CVE-2008-1111 | FEDORA:FEDORA-2008-2278 | View |
333356 | 31228 | CVE-2008-1111 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00180.html | View |
333357 | 31228 | CVE-2008-1111 | GENTOO:GLSA-200803-10 | View |
333358 | 31228 | CVE-2008-1111 | URL:http://security.gentoo.org/glsa/glsa-200803-10.xml | View |
333359 | 31228 | CVE-2008-1111 | SUSE:SUSE-SR:2008:008 | View |
333360 | 31228 | CVE-2008-1111 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html | View |
333361 | 31228 | CVE-2008-1111 | BID:28100 | View |
333362 | 31228 | CVE-2008-1111 | URL:http://www.securityfocus.com/bid/28100 | View |
333363 | 31228 | CVE-2008-1111 | VUPEN:ADV-2008-0763 | View |
333364 | 31228 | CVE-2008-1111 | URL:http://www.vupen.com/english/advisories/2008/0763 | View |
333365 | 31228 | CVE-2008-1111 | SECUNIA:29209 | View |
333366 | 31228 | CVE-2008-1111 | URL:http://secunia.com/advisories/29209 | View |
333367 | 31228 | CVE-2008-1111 | SECUNIA:29268 | View |
333368 | 31228 | CVE-2008-1111 | URL:http://secunia.com/advisories/29268 | View |
333369 | 31228 | CVE-2008-1111 | SECUNIA:29275 | View |
333370 | 31228 | CVE-2008-1111 | URL:http://secunia.com/advisories/29275 | View |
333371 | 31228 | CVE-2008-1111 | SECUNIA:29235 | View |
333372 | 31228 | CVE-2008-1111 | URL:http://secunia.com/advisories/29235 | View |
333373 | 31228 | CVE-2008-1111 | SECUNIA:29318 | View |
333374 | 31228 | CVE-2008-1111 | URL:http://secunia.com/advisories/29318 | View |
333375 | 31228 | CVE-2008-1111 | SECUNIA:29622 | View |
333376 | 31228 | CVE-2008-1111 | URL:http://secunia.com/advisories/29622 | View |
333377 | 31228 | CVE-2008-1111 | XF:lighttpd-modcgi-information-disclosure(41008) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
45827 | JVNDB-2008-001137 | Sun Solaris のディレクトリ関数におけるサービス運用妨害 (DoS) の脆弱性 | Sun Solaris のディレクトリ操作関連の関数には、特定のシステムコールやコマンドの処理に不備があり、サービス運用妨害 (DoS) 状態となる脆弱性が存在します。 | CVE-2008-1115 | 31228 | 4.9 | http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001137.html | View |