|
|
| |
|
| |
lighttpd: symlink attack
| Package(s): | lighttpd |
CVE #(s): | CVE-2013-1427
|
| Created: | March 18, 2013 |
Updated: | March 20, 2013 |
| Description: |
From the Debian advisory:
Stefan Bühler discovered that the Debian specific configuration file for
lighttpd webserver FastCGI PHP support used a fixed socket name in the
world-writable /tmp directory. A symlink attack or a race condition could be
exploited by a malicious user on the same machine to take over the PHP control
socket and for example force the webserver to use a different PHP version. |
| Alerts: |
|
( Log in to post comments)
|
|
|