CVE-2013-4560Use After Free in Lighttpd

CWE-416Use After Free8 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
6.8%
top 8.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 20
Latest updateDec 29

Description

Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

debiandebian/lighttpd< lighttpd 1.4.33-1+nmu1 (bookworm)
NVDlighttpd/lighttpd< 1.4.33
Debianlighttpd/lighttpd< 1.4.33-1+nmu1+3
NVDopensuse/opensuse12.2, 12.3, 13.1+2

Also affects: Debian Linux 6.0, 7.0, 8.0

🔴Vulnerability Details

2
GHSA
GHSA-9r9f-9w9v-wrvp: Use-after-free vulnerability in lighttpd before 12022-05-13
OSV
CVE-2013-4560: Use-after-free vulnerability in lighttpd before 12013-11-20

📋Vendor Advisories

1
Debian
CVE-2013-4560: lighttpd - Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers t...2013

📄Research Papers

1
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware2022-12-29

💬Community

3
Bugzilla
CVE-2013-4560 lighttpd: Use after free if FAMMonitorDirectory fails2013-11-12
Bugzilla
CVE-2013-4560 CVE-2013-4559 lighttpd: various flaws [fedora-all]2013-11-12
Bugzilla
CVE-2013-4560 CVE-2013-4559 lighttpd: various flaws [epel-all]2013-11-12