CVE-2018-19052: Path Traversal
An issue was discovered in modaliasphysicalhandler in modalias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific modalias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19052?
CVE-2018-19052 is a vulnerability in mod_alias_physical_handler in lighttpd before version 1.4.50.
What is the severity of CVE-2018-19052?
CVE-2018-19052 has a severity rating of high with a score of 7.5.
What is the affected software for CVE-2018-19052?
The affected software for CVE-2018-19052 includes Lighttpd before version 1.4.50, openSUSE Backports SLE 15.0 and 15.0-sp1, openSUSE Leap 15.0 and 15.1, SUSE Linux Enterprise Server 11-sp3 and 11-sp4, and Debian Linux 9.0.
How does CVE-2018-19052 impact the system?
CVE-2018-19052 allows for potential path traversal of a single directory above an alias target, which can lead to unauthorized access or disclosure of sensitive information.
How can I fix CVE-2018-19052?
To fix CVE-2018-19052, users should upgrade to lighttpd version 1.4.50 or apply the necessary patches provided by the software vendor.