CVE-2013-4559

NameCVE-2013-4559
Descriptionlighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2795-1
NVD severityhigh (attack range: remote)
Debian Bugs729453
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lighttpd (PTS)squeeze, squeeze (security)1.4.28-2+squeeze1.6fixed
squeeze (lts)1.4.28-2+squeeze1.7fixed
wheezy, wheezy (security)1.4.31-4+deb7u3fixed
stretch, sid, jessie1.4.35-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lighttpdsource(unstable)1.4.33-1+nmu1high729453
lighttpdsourcesqueeze1.4.28-2+squeeze1.4highDSA-2795-1
lighttpdsourcewheezy1.4.31-4+deb7u1highDSA-2795-1

Search for package or bug name: Reporting problems