CVE-2008-4360: Infoleak
Published Oct 3, 2008
·Updated
moduserdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
Affected Software
2 affected components
Lighttpd Lighttpd<1.4.20
Debian Debian Linux=4.0
Remediation
Patch Available
Patch Available
Event History
Oct 3, 2008
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4360?
CVE-2008-4360 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2008-4360?
To mitigate CVE-2008-4360, upgrade to lighttpd version 1.4.20 or later.
3
What versions of lighttpd are affected by CVE-2008-4360?
CVE-2008-4360 affects lighttpd versions prior to 1.4.20.
4
What operating systems are impacted by CVE-2008-4360?
CVE-2008-4360 impacts lighttpd when running on case-insensitive operating systems or filesystems.
5
Can CVE-2008-4360 lead to unauthorized access?
Yes, CVE-2008-4360 can allow remote attackers to bypass intended access restrictions.