Description: A vulnerability has been reported in lighttpd, which can be exploited by malicious people to disclose some potentially sensitive information.
The vulnerability is caused due to an error in the "buffer_urldecode()" function, as encoded control sequences are not correctly handled. This can be exploited to disclose the source code of CGI and FastCGI applications by appending "%00" to the filename in an URL.
The vulnerability has been reported in version 1.3.7 and prior.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.