CVE-2013-1427: Race Condition
The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1427?
CVE-2013-1427 is classified as a low severity vulnerability that can lead to local PHP control socket hijacking.
How do I fix CVE-2013-1427?
To fix CVE-2013-1427, upgrade the Lighttpd server to version 1.4.28 or later.
What type of vulnerability is CVE-2013-1427?
CVE-2013-1427 is a local privilege escalation vulnerability affecting Lighttpd's FastCGI PHP support.
Can CVE-2013-1427 be exploited remotely?
No, CVE-2013-1427 can only be exploited by local users who have access to the system.
Which versions of Lighttpd are affected by CVE-2013-1427?
CVE-2013-1427 affects Lighttpd versions prior to 1.4.28, including multiple earlier releases.