lighttpd CVE-2014-2324 Multiple Directory Traversal Vulnerabilities
BID:66157
Info
lighttpd CVE-2014-2324 Multiple Directory Traversal Vulnerabilities
| Bugtraq ID: | 66157 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2324 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2014 12:00AM |
| Updated: | May 12 2015 07:52PM |
| Credit: | Jann Horn |
| Vulnerable: |
S.u.S.E. openSUSE 13.1 S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 11.4 lighttpd lighttpd 1.4.32 lighttpd lighttpd 1.4.31 lighttpd lighttpd 1.4.30 lighttpd lighttpd 1.4.26 lighttpd lighttpd 1.4.25 lighttpd lighttpd 1.4.24 lighttpd lighttpd 1.4.23 lighttpd lighttpd 1.4.20 lighttpd lighttpd 1.4.19 lighttpd lighttpd 1.4.18 lighttpd lighttpd 1.4.17 lighttpd lighttpd 1.4.16 lighttpd lighttpd 1.4.15 lighttpd lighttpd 1.4.14 lighttpd lighttpd 1.4.13 lighttpd lighttpd 1.4.12 lighttpd lighttpd 1.4.11 lighttpd lighttpd 1.4.10 lighttpd lighttpd 1.4.9 lighttpd lighttpd 1.4.8 lighttpd lighttpd 1.4.7 lighttpd lighttpd 1.4.6 lighttpd lighttpd 1.4.5 lighttpd lighttpd 1.4.4 lighttpd lighttpd 1.4.3 lighttpd lighttpd 1.4.2 lighttpd lighttpd 1.4.1 lighttpd lighttpd 1.4 lighttpd lighttpd 1.3.10 lighttpd lighttpd 1.3.8 lighttpd lighttpd 1.3.7 lighttpd lighttpd 1.4.34 lighttpd lighttpd 1.4.33 IBM Power Systems 780.01 IBM Power Systems 780.00 IBM Power Systems 773.10 IBM Power Systems 773.02 IBM Power Systems 773.00 IBM Power Systems 770.31 IBM Power Systems 770.22 IBM Power Systems 770.21 IBM Power Systems 770.20 IBM Power Systems 770.10 IBM Power Systems 770.00 IBM Power Systems 760.41 IBM Power Systems 760.40 IBM Power Systems 760.31 IBM Power Systems 760.30 IBM Power Systems 760.20 IBM Power Systems 760.11 IBM Power Systems 760.10 IBM Power Systems 760.00 IBM Power Systems 740.81 IBM Power Systems 740.80 IBM Power Systems 740.70 IBM Power Systems 740.61 IBM Power Systems 740.60 IBM Power Systems 740.52 IBM Power Systems 740.51 IBM Power Systems 740.50 IBM Power Systems 740.40 IBM Power Systems 740.21 IBM Power Systems 740.20 IBM Power Systems 740.16 IBM Power Systems 740.15 IBM Power Systems 740.10 IBM Power Systems 740.00 IBM Power Systems 730.91 IBM Power Systems 730.90 IBM Power Systems 730.80 IBM Power Systems 730.72 IBM Power Systems 730.71 IBM Power Systems 730.70 IBM Power Systems 730.61 IBM Power Systems 730.60 IBM Power Systems 730.51 IBM Power Systems 730.50 IBM Power Systems 730.46 IBM Power Systems 730.45 IBM Power Systems 730.40 IBM Power Systems 730.30 IBM Power Systems 730.20 IBM Power Systems 730.00 IBM Power Systems 350.D0 IBM Power Systems 350.C0 IBM Power Systems 350.B1 IBM Power Systems 350.B0 IBM Power Systems 350.A0 IBM Power Systems 350.90 IBM Power Systems 350.80 IBM Power Systems 350.70 IBM Power Systems 350.60 IBM Power Systems 350.50 IBM Power Systems 350.40 IBM Power Systems 350.30 IBM Power Systems 350.20 IBM Power Systems 350.10 IBM Power Systems 350.00 IBM OS/400 V1R5M0 IBM OS/400 V1R4M0 HP vCAS 14.06 (RDA 8.1) HP vCAS 0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
lighttpd lighttpd 1.4.35 HP vCAS 14.10-38402 |
Discussion
lighttpd CVE-2014-2324 Multiple Directory Traversal Vulnerabilities
lighttpd is prone to a multiple directory-traversal vulnerabilities.
A remote attacker could exploit these vulnerabilities using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information.
Versions prior to lighttpd 1.4.35 are vulnerable.
lighttpd is prone to a multiple directory-traversal vulnerabilities.
A remote attacker could exploit these vulnerabilities using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information.
Versions prior to lighttpd 1.4.35 are vulnerable.
Exploit / POC
lighttpd CVE-2014-2324 Multiple Directory Traversal Vulnerabilities
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
lighttpd CVE-2014-2324 Multiple Directory Traversal Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
lighttpd CVE-2014-2324 Multiple Directory Traversal Vulnerabilities
References:
References:
- (CVE-2014-2323, CVE-2014-2324) CVE-2014-2323 CVE-2014-2324 lighttpd: SQL injecti (Red Hat Bugzilla)
- lighttpd Home Page (lighttpd)
- MH01426 - Fix Pack 01AL770_076_032 (IBM)
- MH01427 - Fix Pack 01AM770_076_032 (IBM)
- mod_mysql_vhost SQL injection (lighttpd)
- HPSBGN03191 rev.1 - HP Remote Device Access: Virtual Customer Access System (vCA (HP)
- Security Bulletin: Power Systems Firmware affected by Open Source lighttpd vulne (IBM)