FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-4560

This CVE name corresponds to:

Entered Topic
2014-02-14 lighttpd -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-4560
Phase Assigned(20130612)

Description

Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.

References

Source Reference
MLIST [oss-security] 20131112 Re: CVE Request: lighttpd multiple issues (setuid/... unchecked return value, FAM: read after free)
CONFIRM http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_03.txt
DEBIAN DSA-2795
SUSE openSUSE-SU-2014:0072
SECUNIA 55682