LWN.net Logo

lighttpd: information disclosure

Package(s):lighttpd CVE #(s):CVE-2008-1270
Created:March 13, 2008 Updated:April 10, 2008
Description: From the Mitre advisory: mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.
Alerts:
rPath rPSA-2008-0106-1 2008-03-12
Debian DSA-1521-1 2008-03-16
SuSE SUSE-SR:2008:008 2008-04-04
Gentoo 200804-08 2008-04-10

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.