CVE-2008-1270

Publication date 10 March 2008

Last updated 24 July 2024


Ubuntu priority

Description

mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.

Status

Package Ubuntu Release Status
lighttpd 7.10 gutsy
Fixed 1.4.18-1ubuntu1.3
7.04 feisty
Fixed 1.4.13-9ubuntu4.5
6.10 edgy
Fixed 1.4.13~r1370-1ubuntu1.6
6.06 LTS dapper
Fixed 1.4.11-3ubuntu3.8

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
lighttpd