cbcvebase.
CVE-2014-2324
published 2014-03-14

CVE-2014-2324: Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary…

medium5CVSS 3.1
AVNACLAuNCPINAN
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.

Affected

15 ranges
VendorProductVersion rangeFixed in
contecsv-cpt-mc310_firmware< 6.56.5
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlighttpd< lighttpd 1.4.33-1+nmu3 (bookworm)lighttpd 1.4.33-1+nmu3 (bookworm)
lighttpdlighttpd< 1.4.351.4.35
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
opensuseopensuse
opensuseopensuse
opensuseopensuse
suselinux_enterprise_high_availability_extension
suselinux_enterprise_software_development_kit

CVSS provenance

nvd5.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM