CVE-2013-4559: High severity fipsasp fipscms light vulnerability
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4559?
CVE-2013-4559 is considered a high severity vulnerability due to the potential for privilege escalation.
What systems are affected by CVE-2013-4559?
CVE-2013-4559 affects lighttpd versions before 1.4.33 across various Linux distributions including Debian and openSUSE.
How do I fix CVE-2013-4559?
To fix CVE-2013-4559, upgrade lighttpd to version 1.4.33 or later.
What can attackers do with CVE-2013-4559?
Attackers can exploit CVE-2013-4559 to gain root privileges through improper function return value checks.
Is there a workaround for CVE-2013-4559?
There are no effective workarounds for CVE-2013-4559; patching the vulnerability is recommended.