PT-2013-5074 · Lighttpd+1 · Lighttpd+1

Stefan Bühler

·

Published

2013-11-19

·

Updated

2024-06-15

·

CVE-2013-4559

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions lighttpd versions prior to 1.4.33
Description The issue is related to the failure of lighttpd to check the return value of certain functions, specifically setuid, setgid, and setgroups. This oversight might cause lighttpd to run as root if it is restarted, potentially allowing remote attackers to gain privileges. This can be demonstrated through multiple calls to the clone function, which can cause setuid to fail when the user process limit is reached.
Recommendations For versions prior to 1.4.33, update to version 1.4.33 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources and monitoring system logs for potential exploitation attempts.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4559
DSA-2795-1
MGASA-2013-0334
OPENSUSE-SU-2024:10402-1

Affected Products

Lighttpd
Suse