CVE-2014-2324: Path Traversal
Published Mar 14, 2014
·Updated
Multiple directory traversal vulnerabilities in (1) modevhost and (2) modsimplevhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to requestcheckhostname.
Affected Software
13 affected components
Lighttpd Lighttpd<1.4.35
Debian Debian Linux=6.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
openSUSE openSUSE=11.4
openSUSE openSUSE=12.3
openSUSE openSUSE=13.1
SUSE Linux Enterprise High Availability Extension=11-sp3
SUSE Linux Enterprise Software Development Kit=11-sp3
Contec Sv-cpt-mc310 Firmware<6.5
Contec Sv-cpt-mc310
All of the following
Contec Sv-cpt-mc310 Firmware<6.5
Contec Sv-cpt-mc310
Remediation
Patch Available
Event History
Mar 14, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2324?
CVE-2014-2324 is considered a medium severity vulnerability, as it allows remote attackers to read arbitrary files.
2
How do I fix CVE-2014-2324?
To fix CVE-2014-2324, upgrade to lighttpd version 1.4.35 or later.
3
Which versions of lighttpd are affected by CVE-2014-2324?
Versions of lighttpd prior to 1.4.35 are affected by CVE-2014-2324.
4
What types of systems are impacted by CVE-2014-2324?
CVE-2014-2324 impacts various Linux distributions including Debian and openSUSE that use lighttpd before version 1.4.35.
5
What does CVE-2014-2324 exploit in lighttpd?
CVE-2014-2324 exploits directory traversal vulnerabilities in mod_evhost and mod_simple_vhost.