Description
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2877-1 | lighttpd security update |
References
History
No history.
Subscriptions
Contec
Subscribe
Sv-cpt-mc310
Subscribe
Sv-cpt-mc310 Firmware
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Lighttpd
Subscribe
Lighttpd
Subscribe
Opensuse
Subscribe
Opensuse
Subscribe
Suse
Subscribe
Linux Enterprise High Availability Extension
Subscribe
Linux Enterprise Software Development Kit
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:06:00.322Z
Reserved: 2014-03-12T00:00:00.000Z
Link: CVE-2014-2324
No data.
Status : Deferred
Published: 2014-03-14T15:55:05.760
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-2324
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA