UBUNTU-CVE-2018-19052
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-19052
UBUNTU-CVE-2018-19052
Summary:
Details: An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
References: https://ubuntu.com/security/CVE-2018-19052, https://github.com/lighttpd/lighttpd1.4/commit/2105dae0f9d7a964375ce681e53cb165375f84c1, https://ubuntu.com/security/notices/USN-4775-1, https://www.cve.org/CVERecord?id=CVE-2018-19052
Affected packages
Package
Name: lighttpd
Purl: pkg:deb/ubuntu/[email protected]+nmu2ubuntu2.1+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
