CVE-2013-4560 — Use After Free in Lighttpd
Severity
5.0MEDIUMNVD
EPSS
6.8%
top 8.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 20
Latest updateDec 29
Description
Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages4 packages
Also affects: Debian Linux 6.0, 7.0, 8.0
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2013-4560: lighttpd - Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers t...↗2013
📄Research Papers
1arXiv▶
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware↗2022-12-29