CVE-2014-2323: Debian Linux
Critical severity, CVSS 9.8. EPSS: 62.8% chance of exploitation in the next 30 days.
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
Affected products
- Debian Debian Linux: version 6.0 only; version 7.0 only; version 8.0 only
- Lighttpd Lighttpd: before 1.4.35 (fixed in 1.4.35)
- Opensuse Opensuse: version 11.4 only; version 12.3 only; version 13.1 only
- Suse Linux Enterprise High Availability Extension: version 11 only
- Suse Linux Enterprise Software Development Kit: version 11 only
Published 2014-03-14. Last modified 2026-06-17.