Description
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
Remediation
References
Related Vulnerabilities
WordPress Plugin GiveWP-Donation and Fundraising Platform PHP Object Injection (2.3.0)
WebLogic Improper Handling of Exceptional Conditions Vulnerability (CVE-2017-5638)
Apache Tomcat Other Vulnerability (CVE-2002-1567)
PostgreSQL Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2018-1115)
Question2Answer Improper Input Validation Vulnerability (CVE-2017-12775)