CVE-2018-19792: Buffer Overflow
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19792?
CVE-2018-19792 is classified as a denial of service vulnerability that can lead to a buffer overflow.
How do I fix CVE-2018-19792?
To fix CVE-2018-19792, upgrade LiteSpeed OpenLiteSpeed to version 1.5.0 RC6 or later.
Who is affected by CVE-2018-19792?
CVE-2018-19792 affects local users of LiteSpeed OpenLiteSpeed versions prior to 1.5.0 RC6.
Can CVE-2018-19792 be exploited remotely?
No, CVE-2018-19792 can only be exploited by local users with access to the system.
What type of impact does CVE-2018-19792 have?
CVE-2018-19792 can cause a denial of service or potentially other unspecified impacts due to a buffer overflow.