Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade lighttpd | Aug 30, 2017 | Mar 14, 2014 |
| Debian | — | Upgrade lighttpd | Jul 30, 2024 | Mar 14, 2014 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Dec 8, 2014 | Mar 14, 2014 |
| Oracle Solaris | — | Upgrade web/server/lighttpd-14 to version 1.4.35-0.175.1.21.0.4.0 on Solaris 11.1 | May 29, 2017 | Mar 14, 2014 |
| Suse | — | Upgrade lighttpd-mod_webdavUpgrade lighttpd-mod_cmlUpgrade lighttpd-mod_mysql_vhostUpgrade lighttpd-mod_magnetUpgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpd-mod_rrdtoolUpgrade lighttpd | Dec 18, 2015 | Mar 14, 2014 |
| Ubuntu | — | Upgrade lighttpd | Nov 19, 2024 | Mar 14, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub