[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2649-1 lighttpd -- fixed socket name in world-writable directory

ID: oval:org.secpod.oval:def:600995Date: (C)2013-03-19   (M)2022-10-10
Class: PATCHFamily: unix




Stefan Bühler discovered that the Debian specific configuration file for lighttpd webserver FastCGI PHP support used a fixed socket name in the world-writable /tmp directory. A symlink attack or a race condition could be exploited by a malicious user on the same machine to take over the PHP control socket and for example force the webserver to use a different PHP version. As the fix is in a configuration file lying in /etc, the update won"t be enforced if the file has been modified by the administrator. In that case, care should be taken to manually apply the fix.

Platform:
Debian 6.0
Product:
lighttpd
Reference:
DSA-2649-1
CVE-2013-1427
CVE    1
CVE-2013-1427
CPE    26
cpe:/a:lighttpd:lighttpd:1.4.13
cpe:/a:lighttpd:lighttpd:1.4.12
cpe:/o:debian:debian_linux:6.0
cpe:/a:lighttpd:lighttpd:1.4.11
...

© SecPod Technologies