Description
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-4775-1 | Lighttpd vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:30:04.022Z
Reserved: 2018-11-06T00:00:00.000Z
Link: CVE-2018-19052
No data.
Status : Modified
Published: 2018-11-07T05:29:00.343
Modified: 2024-11-21T03:57:14.017
Link: CVE-2018-19052
No data.
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN