Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:LHTTPD:FCGI-HEADER-OF

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Light HTTPD FastCGI Header Overflow

Release Date

2007/11/01

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Light HTTPD FastCGI Header Overflow


This signature detects attempts to exploit a known vulnerability in lighttpd running the FastCGI module. Versions 1.4.7 and prior are vulnerable. A successful attacker can overflow a header buffer and execute arbitrary code.

Extended Description

Lighttpd is prone to a remote header-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it. An attacker may exploit this issue to overwrite PHP headers such as 'SCRIPT_FILENAME'. This may allow the attacker to execute to script code, obtain sensitive information, and launch other attacks. Exploiting this issue may also aid in the remote compromise of an affected computer. Lighttpd 1.4.17 is vulnerable; prior versions may also be affected.

Affected Products

  • Debian Linux 4.0
  • Debian Linux 4.0 Alpha
  • Debian Linux 4.0 Amd64
  • Debian Linux 4.0 Arm
  • Debian Linux 4.0 Hppa
  • Debian Linux 4.0 Ia-32
  • Debian Linux 4.0 Ia-64
  • Debian Linux 4.0 M68k
  • Debian Linux 4.0 Mips
  • Debian Linux 4.0 Mipsel
  • Debian Linux 4.0 Powerpc
  • Debian Linux 4.0 S/390
  • Debian Linux 4.0 Sparc
  • Foresight Linux 1.1
  • Gentoo Linux
  • lighttpd 1.3.10
  • lighttpd 1.3.7
  • lighttpd 1.3.8
  • lighttpd 1.4.0
  • lighttpd 1.4.1
  • lighttpd 1.4.10
  • lighttpd 1.4.10A
  • lighttpd 1.4.11
  • lighttpd 1.4.12
  • lighttpd 1.4.13
  • lighttpd 1.4.14
  • lighttpd 1.4.15
  • lighttpd 1.4.16
  • lighttpd 1.4.17
  • lighttpd 1.4.2
  • lighttpd 1.4.3
  • lighttpd 1.4.4
  • lighttpd 1.4.5
  • lighttpd 1.4.6
  • lighttpd 1.4.7
  • lighttpd 1.4.8
  • lighttpd 1.4.9
  • Red Hat Fedora Core7
  • rPath rPath Linux 1
  • SuSE Linux 10.0 Ppc
  • SuSE Linux 10.0 X86
  • SuSE Linux 10.0 X86-64
  • SuSE Linux 10.1 Ppc
  • SuSE Linux 10.1 X86
  • SuSE Linux 10.1 X86-64
  • SuSE Linux Desktop 10
  • SuSE Linux Personal 10.0.0 OSS
  • SuSE Linux Personal 10.1
  • SuSE Linux Personal 10.2
  • SuSE Linux Personal 10.2 X86 64
  • SuSE Linux Professional 10.0.0
  • SuSE Linux Professional 10.0.0 OSS
  • SuSE Linux Professional 10.1
  • SuSE Linux Professional 10.2
  • SuSE Linux Professional 10.2 X86 64
  • SuSE Novell Linux Desktop 9.0.0
  • SuSE Novell Linux POS 9
  • SuSE Open-Enterprise-Server
  • SuSE openSUSE 10.2
  • SuSE openSUSE 10.3
  • SuSE SUSE Linux Enterprise Desktop 10
  • SuSE SUSE Linux Enterprise Desktop 10 SP1
  • SuSE SUSE Linux Enterprise SDK 10
  • SuSE SUSE Linux Enterprise SDK 10.SP1
  • SuSE SUSE Linux Enterprise Server 10
  • SuSE SUSE Linux Enterprise Server 10 SP1
  • SuSE SUSE Linux Enterprise Server 8
  • SuSE SuSE Linux Openexchange Server 4.0.0
  • SuSE SUSE LINUX Retail Solution 8.0.0
  • SuSE SuSE Linux School Server for i386
  • SuSE SuSE Linux Standard Server 8.0.0
  • SuSE UnitedLinux 1.0.0

References

  • BugTraq: 25622
  • CVE: CVE-2007-4727
  • URL: http://www.milw0rm.com/exploits/4437
  • URL: http://www.secweb.se/en/advisories/lighttpd-fastcgi-remote-vulnerability/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out