CVE-2008-1111
EPSS 0.99%lighttpd - information disclosure
Published: 3/4/2008Modified: 4/28/2026
Description
mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.
Affected packages (2)
- Debian/lighttpdfrom 0, < 1.4.18-4
- Debian/lighttpdfrom 0, < 1.4.13-4etch5