← Back

CVE-2013-1427

nvd nist
Published: Mar 21, 2013Modified: Apr 29, 2026

JSON object

Loading...
1.9
Vector
AV:L/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 3.4 / Impact: 2.9
Source: NVD

Description

The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.

Affected (24)

Products: Lighttpd: Lighttpd
1 product
Lighttpd
Configuration A
24 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Lighttpd
Up to 1.4.27
Version 1.3.16
Version 1.4.10
Version 1.4.11
Version 1.4.12
Version 1.4.13
Version 1.4.15
Version 1.4.16
Version 1.4.18
Version 1.4.19
Version 1.4.20
Version 1.4.21
Version 1.4.22
Version 1.4.23
Version 1.4.24
Version 1.4.25
Version 1.4.26
Version 1.4.3
Version 1.4.4
Version 1.4.5
Version 1.4.6
Version 1.4.7
Version 1.4.8
Version 1.4.9
Running on/withPlatform Versions
Debian
Debian Linux
All versions

Related CWEs

References (8)

Source: security@debian.org
Source: security@debian.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.