lighttpd < 1.4.34 Multiple Vulnerabilities

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The version of lighttpd running on the remote web server is potentially
affected by multiple vulnerabilities.

Description :

According to its self-reported version, the lighttpd install on the
remote host is a version prior to 1.4.34. It is, therefore, potentially
affected by the following security issues :

- When Server Name Indication (SNI) is enabled, a flaw
exists that could cause the application to use all
available SSL ciphers, including weak ciphers. Remote
attackers could potentially hijack sessions or obtain
sensitive information by sniffing the network.
Note only versions 1.4.24 to 1.4.33 are affected.
(CVE-2013-4508)

- A flaw exists in the clang static analyzer because it
fails to perform checks around setuid (1), setgid (2),
and setgroups (3) calls. This could allow a remote
attacker to gain elevated privileges. (CVE-2013-4559)

- A use-after-free error exists in the clang static
analyzer, when the FAM stat cache engine is enabled.
This could allow remote attackers to dereference
already freed memory and crash the program.
(CVE-2013-4560)

Note that Nessus has not tested for this issue but has instead relied
only on the version in the server's banner.

See also :

http://www.lighttpd.net/2014/1/20/1-4-34/
http://redmine.lighttpd.net/issues/2525
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_01.txt
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_02.txt
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_03.txt

Solution :

Either upgrade to lighttpd version 1.4.34 or later or apply the
vendor's patch.

Risk factor :

High / CVSS Base Score : 7.6
(CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.6
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 72815 ()

Bugtraq ID: 63534
63686
63688

CVE ID: CVE-2013-4508
CVE-2013-4559
CVE-2013-4560