VYPR
Medium severity5.3OSV Advisory· Published Jun 17, 2024· Updated Jun 17, 2026

CVE-2018-25103

CVE-2018-25103

Description

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Lighttpd/LighttpdOSV2 versions
    lighttpd-1.3.11, lighttpd-1.3.12, lighttpd-1.3.13, …+ 1 more
    • (no CPE)range: lighttpd-1.3.11, lighttpd-1.3.12, lighttpd-1.3.13, …
    • (no CPE)range: <=1.4.50

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.