Short Name |
HTTP:LHTTPD:FCGI-HEADER-OF
|
Severity |
High
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Light HTTPD FastCGI Header Overflow
|
Release Date |
2007/11/01
|
Update Number |
1213
|
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: Light HTTPD FastCGI Header Overflow
This signature detects attempts to exploit a known vulnerability in lighttpd running the FastCGI module. Versions 1.4.7 and prior are vulnerable. A successful attacker can overflow a header buffer and execute arbitrary code.
Extended Description
Lighttpd is prone to a remote header-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it.
An attacker may exploit this issue to overwrite PHP headers such as 'SCRIPT_FILENAME'. This may allow the attacker to execute to script code, obtain sensitive information, and launch other attacks. Exploiting this issue may also aid in the remote compromise of an affected computer.
Lighttpd 1.4.17 is vulnerable; prior versions may also be affected.
Affected Products
- Debian Linux 4.0
- Debian Linux 4.0 Alpha
- Debian Linux 4.0 Amd64
- Debian Linux 4.0 Arm
- Debian Linux 4.0 Hppa
- Debian Linux 4.0 Ia-32
- Debian Linux 4.0 Ia-64
- Debian Linux 4.0 M68k
- Debian Linux 4.0 Mips
- Debian Linux 4.0 Mipsel
- Debian Linux 4.0 Powerpc
- Debian Linux 4.0 S/390
- Debian Linux 4.0 Sparc
- Foresight Linux 1.1
- Gentoo Linux
- lighttpd 1.3.10
- lighttpd 1.3.7
- lighttpd 1.3.8
- lighttpd 1.4.0
- lighttpd 1.4.1
- lighttpd 1.4.10
- lighttpd 1.4.10A
- lighttpd 1.4.11
- lighttpd 1.4.12
- lighttpd 1.4.13
- lighttpd 1.4.14
- lighttpd 1.4.15
- lighttpd 1.4.16
- lighttpd 1.4.17
- lighttpd 1.4.2
- lighttpd 1.4.3
- lighttpd 1.4.4
- lighttpd 1.4.5
- lighttpd 1.4.6
- lighttpd 1.4.7
- lighttpd 1.4.8
- lighttpd 1.4.9
- Red Hat Fedora Core7
- rPath rPath Linux 1
- SuSE Linux 10.0 Ppc
- SuSE Linux 10.0 X86
- SuSE Linux 10.0 X86-64
- SuSE Linux 10.1 Ppc
- SuSE Linux 10.1 X86
- SuSE Linux 10.1 X86-64
- SuSE Linux Desktop 10
- SuSE Linux Personal 10.0.0 OSS
- SuSE Linux Personal 10.1
- SuSE Linux Personal 10.2
- SuSE Linux Personal 10.2 X86 64
- SuSE Linux Professional 10.0.0
- SuSE Linux Professional 10.0.0 OSS
- SuSE Linux Professional 10.1
- SuSE Linux Professional 10.2
- SuSE Linux Professional 10.2 X86 64
- SuSE Novell Linux Desktop 9.0.0
- SuSE Novell Linux POS 9
- SuSE Open-Enterprise-Server
- SuSE openSUSE 10.2
- SuSE openSUSE 10.3
- SuSE SUSE Linux Enterprise Desktop 10
- SuSE SUSE Linux Enterprise Desktop 10 SP1
- SuSE SUSE Linux Enterprise SDK 10
- SuSE SUSE Linux Enterprise SDK 10.SP1
- SuSE SUSE Linux Enterprise Server 10
- SuSE SUSE Linux Enterprise Server 10 SP1
- SuSE SUSE Linux Enterprise Server 8
- SuSE SuSE Linux Openexchange Server 4.0.0
- SuSE SUSE LINUX Retail Solution 8.0.0
- SuSE SuSE Linux School Server for i386
- SuSE SuSE Linux Standard Server 8.0.0
- SuSE UnitedLinux 1.0.0
References