Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Debian DSA-2877-1 Critical: Lighttpd MySQL Injection and Path Traversal

debian
Calendar Grey March 13, 2014
Scroller Debian
A recent lighttpd update responds to significant vulnerabilities that compromise web server safety, particularly regarding MySQL integration.
Several vulnerabilities were discovered in the lighttpd web server

Summary

CVE-2014-2323

Jann Horn discovered that specially crafted host names can be used
to inject arbitrary MySQL queries in lighttpd servers using the
MySQL virtual hosting module (mod_mysql_vhost).

This only affects installations with the lighttpd-mod-mysql-vhost
binary package installed and in use.

CVE-2014-2324

Jann Horn discovered that specially crafted host names can be used
to traverse outside of the document root under certain situations
in lighttpd servers using either the mod_mysql_vhost, mod_evhost,
or mod_simple_vhost virtual hosting modules.

Servers not using these modules are not affected.

For the oldstable distribution (squeeze), these problems have been fixed in
version 1.4.28-2+squeeze1.6.

For the stable distribution (wheezy), these problems have been fixed in
version 1.4.31-4+deb7u3.

For the testing distribution (jessie), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in
version 1.4.33-1+nmu3.

We...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: lighttpd
CVE ID: CVE-2014-2323 CVE-2014-2324

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.