CVE-2013-4559

NameCVE-2013-4559
Descriptionlighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2795-1
NVD severityhigh (attack range: remote)
Debian Bugs729453

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lighttpd (PTS)wheezy (security), wheezy1.4.31-4+deb7u4fixed
jessie1.4.35-4fixed
stretch, sid1.4.39-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lighttpdsource(unstable)1.4.33-1+nmu1high729453
lighttpdsourcesqueeze1.4.28-2+squeeze1.4highDSA-2795-1
lighttpdsourcewheezy1.4.31-4+deb7u1highDSA-2795-1

Search for package or bug name: Reporting problems