Candidate: CVE-2015-3200 PublicDate: 2015-06-09 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3200 http://jaanuskp.blogspot.com/2015/05/cve-2015-3200.html Description: mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character. Ubuntu-Description: Notes: Bugs: http://redmine.lighttpd.net/issues/2646 https://web.archive.org/web/20160907194723/http://jaanuskp.blogspot.com/2015/05/cve-2015-3200.html Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_lighttpd: upstream: https://github.com/lighttpd/lighttpd1.4/commit/427120b41a141626dbb40a752c848f199fc9f7a8 upstream_lighttpd: released (1.4.37-1) precise_lighttpd: ignored (reached end-of-life) precise/esm_lighttpd: DNE (precise was needs-triage) trusty_lighttpd: ignored (reached end-of-life) trusty/esm_lighttpd: DNE (trusty was needed) utopic_lighttpd: ignored (reached end-of-life) vivid_lighttpd: ignored (reached end-of-life) vivid/stable-phone-overlay_lighttpd: DNE vivid/ubuntu-core_lighttpd: DNE wily_lighttpd: ignored (reached end-of-life) xenial_lighttpd: ignored (end of standard support, was needed) yakkety_lighttpd: ignored (reached end-of-life) zesty_lighttpd: ignored (reached end-of-life) artful_lighttpd: ignored (reached end-of-life) bionic_lighttpd: not-affected (1.4.45-1ubuntu3) cosmic_lighttpd: not-affected (1.4.45-1ubuntu3) disco_lighttpd: not-affected (1.4.45-1ubuntu3) eoan_lighttpd: not-affected (1.4.45-1ubuntu3) focal_lighttpd: not-affected (1.4.45-1ubuntu3) groovy_lighttpd: not-affected (1.4.45-1ubuntu3) hirsute_lighttpd: not-affected (1.4.45-1ubuntu3) impish_lighttpd: not-affected (1.4.45-1ubuntu3) jammy_lighttpd: not-affected (1.4.45-1ubuntu3) devel_lighttpd: not-affected (1.4.45-1ubuntu3)