CVE Vulnerabilities

CVE-2013-1427

Published: Mar 21, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.

Affected Software

NameVendorStart VersionEnd Version
LighttpdLighttpd*1.4.27 (including)
LighttpdLighttpd1.3.16 (including)1.3.16 (including)
LighttpdLighttpd1.4.3 (including)1.4.3 (including)
LighttpdLighttpd1.4.4 (including)1.4.4 (including)
LighttpdLighttpd1.4.5 (including)1.4.5 (including)
LighttpdLighttpd1.4.6 (including)1.4.6 (including)
LighttpdLighttpd1.4.7 (including)1.4.7 (including)
LighttpdLighttpd1.4.8 (including)1.4.8 (including)
LighttpdLighttpd1.4.9 (including)1.4.9 (including)
LighttpdLighttpd1.4.10 (including)1.4.10 (including)
LighttpdLighttpd1.4.11 (including)1.4.11 (including)
LighttpdLighttpd1.4.12 (including)1.4.12 (including)
LighttpdLighttpd1.4.13 (including)1.4.13 (including)
LighttpdLighttpd1.4.15 (including)1.4.15 (including)
LighttpdLighttpd1.4.16 (including)1.4.16 (including)
LighttpdLighttpd1.4.18 (including)1.4.18 (including)
LighttpdLighttpd1.4.19 (including)1.4.19 (including)
LighttpdLighttpd1.4.20 (including)1.4.20 (including)
LighttpdLighttpd1.4.21 (including)1.4.21 (including)
LighttpdLighttpd1.4.22 (including)1.4.22 (including)
LighttpdLighttpd1.4.23 (including)1.4.23 (including)
LighttpdLighttpd1.4.24 (including)1.4.24 (including)
LighttpdLighttpd1.4.25 (including)1.4.25 (including)
LighttpdLighttpd1.4.26 (including)1.4.26 (including)
LighttpdUbuntuhardy*
LighttpdUbuntulucid*
LighttpdUbuntuoneiric*
LighttpdUbuntuprecise*
LighttpdUbuntuquantal*
LighttpdUbunturaring*
LighttpdUbuntusaucy*
LighttpdUbuntuupstream*

References