CVE-2008-1270 when mod_userdir is loaded but not configured, the server's whole disk becomes remotely readable
Bug #200987 reported by
Emanuele Gentili
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
lighttpd (Ubuntu) |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Dapper |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Edgy |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Feisty |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Gutsy |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Hardy |
Fix Released
|
Medium
|
Emanuele Gentili |
Bug Description
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.
http://
http://
Changed in lighttpd: | |
status: | New → Confirmed |
status: | New → Confirmed |
status: | New → Confirmed |
status: | New → Confirmed |
status: | New → Confirmed |
Changed in lighttpd: | |
assignee: | nobody → emgent |
importance: | Undecided → Medium |
status: | Confirmed → In Progress |
Changed in lighttpd: | |
assignee: | nobody → emgent |
importance: | Undecided → Medium |
status: | Confirmed → In Progress |
Changed in lighttpd: | |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
To post a comment you must log in.
This bug was fixed in the package lighttpd - 1.4.18-1ubuntu6
---------------
lighttpd (1.4.18-1ubuntu6) hardy; urgency=low
* SECURITY UPDATE: (LP: #200987) patches/ 91_CVE- 2008-1270. dpatch trac.lighttpd. net/trac/ ticket/ 1587 trac.lighttpd. net/trac/ changeset/ 2120
+ debian/
- mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set,
uses a default of $HOME, which might allow remote attackers to read arbitrary
files, as demonstrated by accessing the ~nobody directory.
* References
+ CVE-2008-1270
+ http://
+ http://
-- Emanuele Gentili <email address hidden> Tue, 11 Mar 2008 14:16:48 +0100