CVE-2011-4362 describes an integer signedness error in the base64_decode function within lighttpd versions 1.4 before 1.4.30 and 1.5 before SVN revision 2806. This flaw allows remote attackers to trigger a denial of service (segmentation fault) by providing specially crafted base64 input, leading to an out-of-bounds read with a negative index. The vulnerability has a CVSS score of 5.0, indicating a medium severity, with low attack complexity and no authentication required, resulting in a partial availability impact. While not actively exploited in the wild, a proof-of-concept exploit is available on ExploitDB, and there is no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.1, < 1.4.30CPE matchmatch criteria | cpe:2.3:a:lighttpd:lighttpd:*:*:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:lighttpd:lighttpd:1.5.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.