CVE-2013-4560: Use After Free
Published Nov 19, 2013
·Updated
Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.
Affected Software
8 affected componentsFixes available
debian/lighttpd
1.4.53-4+deb10u21.4.53-4+deb10u31.4.59-1+deb11u21.4.69-1
Lighttpd Lighttpd<1.4.33
Debian Debian Linux=6.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
openSUSE openSUSE=12.2
openSUSE openSUSE=12.3
openSUSE openSUSE=13.1
Event History
Nov 19, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4560?
CVE-2013-4560 has a severity rating that may lead to denial of service due to a segmentation fault.
2
How do I fix CVE-2013-4560?
To fix CVE-2013-4560, upgrade to lighttpd version 1.4.33 or later.
3
What versions of lighttpd are affected by CVE-2013-4560?
CVE-2013-4560 affects all lighttpd versions prior to 1.4.33.
4
Can CVE-2013-4560 be exploited remotely?
Yes, CVE-2013-4560 can be exploited remotely, causing a denial of service.
5
Which operating systems are impacted by CVE-2013-4560?
CVE-2013-4560 impacts Debian and openSUSE operating systems with affected versions of lighttpd.