lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
| Software | From | Fixed in |
|---|---|---|
| lighttpd / lighttpd | 1.4.24 | 1.4.33.x |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 7.0 | 7.0.x |
| debian / debian_linux | 6.0 | 6.0.x |
| opensuse / opensuse | 12.3 | 12.3.x |
| opensuse / opensuse | 12.2 | 12.2.x |
| opensuse / opensuse | 13.1 | 13.1.x |