Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jp3-8rhj-499h

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function.

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function.

EPSS

Процентиль: 19%
0.00062
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 6.7
nvd
около 7 лет назад

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function.

EPSS

Процентиль: 19%
0.00062
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-119