Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-4508
Description:lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
Test IDs: 1.3.6.1.4.1.25623.1.0.702795  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-4508
DSA-2795
https://www.debian.org/security/2013/dsa-2795
HPSBGN03191
http://marc.info/?l=bugtraq&m=141576815022399&w=2
JVN#37417423
http://jvn.jp/en/jp/JVN37417423/index.html
[oss-security] 20131104 Re: CVE Request: lighttpd using vulnerable cipher suites with SNI
http://openwall.com/lists/oss-security/2013/11/04/19
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_01.txt
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_01.txt
http://redmine.lighttpd.net/issues/2525
http://redmine.lighttpd.net/issues/2525
http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2913/diff/
http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2913/diff/
openSUSE-SU-2014:0072
http://lists.opensuse.org/opensuse-updates/2014-01/msg00049.html




© 1998-2025 E-Soft Inc. All rights reserved.