alpine · CVE-2015-3200

Quick triage

Priority: high 公開: Updated:

参照: Official alpine advisory, NVD, CVE.org · CVE 詳細

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2015-3200: 1 source package rows (lighttpd); 5 state rows across 5 repos (3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 0, open 5.

Description:

mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.

cvelogic Threat Intelligence