CVE-2008-4360
published 2008-10-03CVE-2008-4360: mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.35%
90.2th percentile
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | lighttpd | < lighttpd 1.4.19-5 (bookworm) | lighttpd 1.4.19-5 (bookworm) |
| lighttpd | lighttpd | < 1.4.20 | 1.4.20 |
| lighttpd | lighttpd | >= 0 < 1.4.19-5 | 1.4.19-5 |
| lighttpd | lighttpd | >= 0 < 1.4.19-5 | 1.4.19-5 |
| lighttpd | lighttpd | >= 0 < 1.4.19-5 | 1.4.19-5 |
| lighttpd | lighttpd | >= 0 < 1.4.19-5 | 1.4.19-5 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-73r4-8h5j-2cjg: mod_userdir in lighttpd before 1
ghsa_unreviewed·2022-05-02
CVE-2008-4360 [HIGH] CWE-200 GHSA-73r4-8h5j-2cjg: mod_userdir in lighttpd before 1
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
OSV
CVE-2008-4360: mod_userdir in lighttpd before 1
osv·2008-10-03·CVSS 7.5
CVE-2008-4360 [HIGH] CVE-2008-4360: mod_userdir in lighttpd before 1
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
Red Hat
lighttpd: mod_userdir information disclosure on case-insensitve filesystems
vendor_redhat·2008-03-11·CVSS 7.5
CVE-2008-4360 [HIGH] lighttpd: mod_userdir information disclosure on case-insensitve filesystems
lighttpd: mod_userdir information disclosure on case-insensitve filesystems
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
Debian
CVE-2008-4360: lighttpd - mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system ...
vendor_debian·2008·CVSS 7.5
CVE-2008-4360 [HIGH] CVE-2008-4360: lighttpd - mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system ...
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.
Scope: local
bookworm: resolved (fixed in 1.4.19-5)
bullseye: resolved (fixed in 1.4.19-5)
forky: resolved (fixed in 1.4.19-5)
sid: resolved (fixed in 1.4.19-5)
trixie: resolved (fixed in 1.4.19-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-4360 lighttpd: mod_userdir information disclosure on case-insensitve filesystems
bugzilla·2008-10-06·CVSS 7.5
CVE-2008-4360 [HIGH] CVE-2008-4360 lighttpd: mod_userdir information disclosure on case-insensitve filesystems
CVE-2008-4360 lighttpd: mod_userdir information disclosure on case-insensitve filesystems
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4360 to the following vulnerability:
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system
or filesystem is used, performs case-sensitive comparisons on filename
components in configuration options, which might allow remote attackers to
bypass intended access restrictions, as demonstrated by a request for a .PHP
file when there is a configuration rule for .php files.
Affected versions:
all versions before 1.4.20 (1.5 before r2308)
Upstream advisory:
http://www.lighttpd.net/security/lighttpd_sa_2008_06.txt
Upstream bug report:
http://trac.lighttpd.net/trac/ticket/1589
Upstream patches (1.4.x):
http://ww
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 8]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 8]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%208&bugs=464638,
---
New bodhi link:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%208&bugs=464638,CVE-2008-4298,CVE-2008-4359,CVE-2008-4360
---
This message is a reminder that Fedora 8 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 8. It is Fedora's policy to close all
bu
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-4]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-4]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-4]
epel-4 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
I had forgotten to close this report, doing so now.
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-5]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-5]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-5]
epel-5 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
I had forgotten to close this report, doing so now.
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 9]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 9]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=464639,
---
New bodhi link:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=464639,CVE-2008-4298,CVE-2008-4359,CVE-2008-4360
---
lighttpd-1.4.20-6.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/lighttpd-1.4.20-6.fc9
---
lighttpd-1.4.20-6.fc9 has been pushed to the Fedora 9 testing repository.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://openwall.com/lists/oss-security/2008/09/30/1http://openwall.com/lists/oss-security/2008/09/30/2http://openwall.com/lists/oss-security/2008/09/30/3http://secunia.com/advisories/32069http://secunia.com/advisories/32132http://secunia.com/advisories/32480http://secunia.com/advisories/32834http://secunia.com/advisories/32972http://security.gentoo.org/glsa/glsa-200812-04.xmlhttp://trac.lighttpd.net/trac/changeset/2283http://trac.lighttpd.net/trac/changeset/2308http://trac.lighttpd.net/trac/ticket/1589http://wiki.rpath.com/Advisories:rPSA-2008-0309http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309http://www.debian.org/security/2008/dsa-1645http://www.lighttpd.net/security/lighttpd-1.4.x_userdir_lowercase.patchhttp://www.lighttpd.net/security/lighttpd_sa_2008_06.txthttp://www.securityfocus.com/archive/1/497932/100/0/threadedhttp://www.securityfocus.com/bid/31600http://www.vupen.com/english/advisories/2008/2741https://exchange.xforce.ibmcloud.com/vulnerabilities/45689http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://openwall.com/lists/oss-security/2008/09/30/1http://openwall.com/lists/oss-security/2008/09/30/2http://openwall.com/lists/oss-security/2008/09/30/3http://secunia.com/advisories/32069http://secunia.com/advisories/32132http://secunia.com/advisories/32480http://secunia.com/advisories/32834http://secunia.com/advisories/32972http://security.gentoo.org/glsa/glsa-200812-04.xmlhttp://trac.lighttpd.net/trac/changeset/2283http://trac.lighttpd.net/trac/changeset/2308http://trac.lighttpd.net/trac/ticket/1589http://wiki.rpath.com/Advisories:rPSA-2008-0309http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309http://www.debian.org/security/2008/dsa-1645http://www.lighttpd.net/security/lighttpd-1.4.x_userdir_lowercase.patchhttp://www.lighttpd.net/security/lighttpd_sa_2008_06.txthttp://www.securityfocus.com/archive/1/497932/100/0/threadedhttp://www.securityfocus.com/bid/31600http://www.vupen.com/english/advisories/2008/2741https://exchange.xforce.ibmcloud.com/vulnerabilities/45689
2008-10-03
Published