LWN.net Logo

lighttpd: symlink attack

Package(s):lighttpd CVE #(s):CVE-2013-1427
Created:March 18, 2013 Updated:March 20, 2013
Description: From the Debian advisory:

Stefan Bühler discovered that the Debian specific configuration file for lighttpd webserver FastCGI PHP support used a fixed socket name in the world-writable /tmp directory. A symlink attack or a race condition could be exploited by a malicious user on the same machine to take over the PHP control socket and for example force the webserver to use a different PHP version.

Alerts:
Debian DSA-2649-1 2013-03-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds