Vulnerability Description
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lighttpd | Lighttpd | < 1.4.20 |
| Debian | Debian Linux | 4.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlThird Party Advisory
- http://openwall.com/lists/oss-security/2008/09/30/1Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2008/09/30/2Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2008/09/30/3Mailing ListThird Party Advisory
- http://secunia.com/advisories/32069Third Party Advisory
- http://secunia.com/advisories/32132Third Party Advisory
- http://secunia.com/advisories/32480Third Party Advisory
- http://secunia.com/advisories/32834Third Party Advisory
- http://secunia.com/advisories/32972Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-04.xmlThird Party Advisory
- http://trac.lighttpd.net/trac/changeset/2283Broken LinkVendor Advisory
- http://trac.lighttpd.net/trac/changeset/2308Broken LinkVendor Advisory
- http://trac.lighttpd.net/trac/ticket/1589PatchVendor Advisory
- http://wiki.rpath.com/Advisories:rPSA-2008-0309Third Party Advisory
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309Third Party Advisory
FAQ
What is CVE-2008-4360?
CVE-2008-4360 is a vulnerability with a CVSS score of 7.5 (HIGH). mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might ...
How severe is CVE-2008-4360?
CVE-2008-4360 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4360?
Check the references section above for vendor advisories and patch information. Affected products include: Lighttpd Lighttpd, Debian Debian Linux.