CVE-2008-4360
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.35% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- lighttpd/lighttpd · debian/debian linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlThird Party Advisory
- http://openwall.com/lists/oss-security/2008/09/30/1Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2008/09/30/2Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2008/09/30/3Mailing List, Third Party Advisory
- http://secunia.com/advisories/32069Third Party Advisory
- http://secunia.com/advisories/32132Third Party Advisory
- http://secunia.com/advisories/32480Third Party Advisory
- http://secunia.com/advisories/32834Third Party Advisory
- http://secunia.com/advisories/32972Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-04.xmlThird Party Advisory
- http://trac.lighttpd.net/trac/changeset/2283Broken Link, Vendor Advisory
- http://trac.lighttpd.net/trac/changeset/2308Broken Link, Vendor Advisory
- http://trac.lighttpd.net/trac/ticket/1589Patch, Vendor Advisory
- http://wiki.rpath.com/Advisories:rPSA-2008-0309Third Party Advisory
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309Third Party Advisory
- http://www.debian.org/security/2008/dsa-1645Third Party Advisory
- http://www.lighttpd.net/security/lighttpd-1.4.x_userdir_lowercase.patchPatch, Vendor Advisory
- http://www.lighttpd.net/security/lighttpd_sa_2008_06.txtPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/497932/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31600Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2741Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45689Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlThird Party Advisory
- http://openwall.com/lists/oss-security/2008/09/30/1Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2008/09/30/2Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2008/09/30/3Mailing List, Third Party Advisory
- http://secunia.com/advisories/32069Third Party Advisory
- http://secunia.com/advisories/32132Third Party Advisory
- http://secunia.com/advisories/32480Third Party Advisory
- http://secunia.com/advisories/32834Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.