← Back

CVE-2018-19052

nvd nist
Published: Nov 7, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.

Affected (13)

Show all products
1 product
Lighttpd
2 products
Backports Sle
Leap
1 product
Suse Linux Enterprise Server
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.50
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.0 sp1
Opensuse
Version 15.0
Version 15.1
Suse
Version 11 sp3
Version 11 sp4
Version 12
Version 12 sp1
Version 12 sp2
Version 12 sp3
Version 12 sp4
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

References (6)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.