CVE-2007-4727: Buffer Overflow
Buffer overflow in the fcgienvadd function in modproxybackendfastcgi.c in the modfastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPTFILENAME variable, aka a "header overflow."
Other sources
Description of problem:
New 1.4.18 release of lighttpd fixes an arbitrary code execution flaw in lighttpd's header parsing code. Please update the package.
Additional info:
http://secweb.se/en/advisories/lighttpd-fastcgi-remote-vulnerability/ http://www.lighttpd.net/assets/2007/9/9/lighttpdsa200712.txt
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4727?
CVE-2007-4727 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2007-4727?
To fix CVE-2007-4727, you should upgrade to lighttpd version 1.4.18 or later.
What types of systems are affected by CVE-2007-4727?
CVE-2007-4727 affects lighttpd versions prior to 1.4.18, particularly systems using the mod_fastcgi extension.
Can CVE-2007-4727 be exploited remotely?
Yes, CVE-2007-4727 can be exploited remotely via specially crafted HTTP requests.
What impact does CVE-2007-4727 have on servers?
CVE-2007-4727 can lead to arbitrary code execution, potentially compromising server integrity and security.