CVE-2011-4362

Publication date 24 December 2011

Last updated 24 July 2024


Ubuntu priority

Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via crafted base64 input that triggers an out-of-bounds read with a negative index.

Status

Package Ubuntu Release Status
lighttpd 11.10 oneiric
Fixed 1.4.28-2ubuntu2.1
11.04 natty
Fixed 1.4.28-2ubuntu1.1
10.10 maverick
Fixed 1.4.26-3ubuntu2.1
10.04 LTS lucid
Fixed 1.4.26-1.1ubuntu3.1
8.04 LTS hardy Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
lighttpd