mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lighttpd | Jul 30, 2024 | Oct 3, 2008 |
| Freebsd | — | Upgrade lighttpd | Dec 10, 2025 | Sep 27, 2008 |
| Gentoo Linux | — | Upgrade www-servers/lighttpd. | Oct 30, 2017 | Oct 3, 2008 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Dec 8, 2014 | Oct 3, 2008 |
| Suse | — | Upgrade lighttpd-mod_cmlUpgrade lighttpd-mod_webdavUpgrade suse-releaseUpgrade lighttpd-mod_mysql_vhostUpgrade lighttpdUpgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpd-mod_magnetUpgrade lighttpd-mod_rrdtool | Feb 17, 2015 | Oct 3, 2008 |
| Ubuntu | — | Upgrade lighttpd | Nov 19, 2024 | Oct 3, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub