CVE-2013-4508: Debian Linux

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.

Affected products

  • Debian Debian Linux: version 6.0 only; version 7.0 only; version 8.0 only
  • Lighttpd Lighttpd: from 1.4.24, up to and including 1.4.33
  • Opensuse Opensuse: version 12.2 only; version 12.3 only; version 13.1 only

Published 2013-11-08. Last modified 2026-06-16.