Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Intel and Lenovo BMC have unpatched Lighttpd server flaw
    Cyber Security

    Intel and Lenovo BMC have unpatched Lighttpd server flaw

    techempireBy techempire4 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportApril 15, 2024Editorial DepartmentFirmware Security/Vulnerabilities

    Intel and Lenovo BMC

    New findings from Binarly reveal that equipment vendors such as Intel and Lenovo have still not patched a security vulnerability affecting the Lighttpd web server used in the baseboard management controller (BMC).

    While the original flaw was discovered and patched by Lighttpd maintainers back in August 2018 in version 1.4.51, the lack of a CVE identifier or advisory meant it was ignored by the developers of AMI MegaRAC BMC and ended up appearing in the product. Provided by Intel and Lenovo.

    Lighttpd (pronounced “Lighty”) is open source, high-performance web server software designed for speed, security, and flexibility, while being optimized for high-performance environments without consuming large amounts of system resources.

    Lighttpd’s silent fix involves an out-of-bounds read vulnerability that can be exploited to leak sensitive data such as process memory addresses, allowing threat actors to bypass critical security mechanisms such as Address Space Layout Randomization (ASLR).

    Internet security

    “The lack of timely and critical information about security fixes hinders the proper processing of these fixes along the firmware and software supply chain,” the firmware security company said.

    The defect description is as follows –

    • Out-of-bounds read in Lighttpd 1.4.45 used in Intel M70KLP series firmware
    • Out-of-bounds read in Lighttpd 1.4.35 used in Lenovo BMC firmware
    • Out-of-bounds read in Lighttpd before 1.4.51

    Intel and Lenovo chose not to address the issue because products containing vulnerable versions of Lighttpd have reached end-of-life (EoL) status and are no longer eligible for security updates, effectively turning them into bugs forever.

    Intel and Lenovo BMC

    The disclosure highlights how outdated third-party components in the latest versions of firmware can traverse the supply chain and pose unexpected security risks to end users.

    Binarly added: “This is another vulnerability that will never be fixed in some products and will pose a high impact risk to the industry for a long time to come.”

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.