Permissions, Privileges, and Access Controls in lighttpd - CVE-2013-4559
Published: November 20, 2013 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.
Affected software
Gentoo Linux
Amazon Linux AMI
Fedora
lighttpd (Alpine package)
lighttpd
Adobe Commerce (formerly Magento Commerce)
Virtual Customer Access System (vCAS)
How to mitigate CVE-2013-4559
lighttpd (Alpine package) - update to 1.4.33-r1
lighttpd - addressed in versions 1.4.34-1.el5.1, 1.4.34-1.el6
Virtual Customer Access System (vCAS) - update to 14.10-38402
External References
- http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_02.txt
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00049.html
- http://marc.info/?l=bugtraq&m=141576815022399&w=2
- http://secunia.com/advisories/55682
- http://www.openwall.com/lists/oss-security/2013/11/12/4
- https://kc.mcafee.com/corporate/index?page=content&id=SB10310
- https://www.debian.org/security/2013/dsa-2795
Related Security Bulletins
- Permissions, Privileges, and Access Controls in lighttpd
- Permissions, Privileges, and Access Controls in lighttpd (Alpine package)
- Amazon Linux AMI update for lighttpd
- Gentoo update for lighttpd
- Multiple vulnerabilities in HP Remote Device Access: Virtual Customer Access System (vCAS)
- Fedora EPEL 6 update for lighttpd
- Fedora EPEL 5 update for lighttpd