Privilege escalation in lighttpd - #VU338
Published: August 20, 2016
lighttpd
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect symlink handling in stat_cache, when “server.follow-symlink” is set to “disable”. A local attacker can overwrite arbitrary files on the target system with privileges of the web server.
Successful exploitation of this vulnerability may allow a local user to obtain elevated privileges.