Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-1427

Опубликовано: 21 мар. 2013
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 1.9

Описание

The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.

РелизСтатусПримечание
devel

not-affected

1.4.33-1+nmu2ubuntu2
esm-apps/xenial

not-affected

1.4.33-1+nmu2ubuntu2
esm-infra-legacy/trusty

not-affected

1.4.33-1+nmu2ubuntu2
hardy

ignored

end of life
lucid

ignored

end of life
oneiric

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life
raring

ignored

end of life

Показывать по

Ссылки на источники

EPSS

Процентиль: 12%
0.0004
Низкий

1.9 Low

CVSS2

Связанные уязвимости

nvd
почти 13 лет назад

The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.

debian
почти 13 лет назад

The configuration file for the FastCGI PHP support for lighttpd before ...

github
больше 3 лет назад

The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.

EPSS

Процентиль: 12%
0.0004
Низкий

1.9 Low

CVSS2