cbcvebase.
CVE-2014-2324
published 2014-03-14

CVE-2014-2324: Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary…

PriorityP340medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
28.81%
97.9th percentile
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.

Affected

15 ranges
VendorProductVersion rangeFixed in
contecsv-cpt-mc310_firmware< 6.56.5
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlighttpd< lighttpd 1.4.33-1+nmu3 (bookworm)lighttpd 1.4.33-1+nmu3 (bookworm)
lighttpdlighttpd< 1.4.351.4.35
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
lighttpdlighttpd>= 0 < 1.4.33-1+nmu31.4.33-1+nmu3
opensuseopensuse
opensuseopensuse
opensuseopensuse
suselinux_enterprise_high_availability_extension
suselinux_enterprise_software_development_kit

Detection & IOCsextracted from sources · hover to see the quote

  • Directory traversal attack vector: attacker places '..' (dot dot) sequences in the HTTP Host header, exploiting mod_evhost or mod_simple_vhost to read arbitrary files outside the web root.
  • Specifically, do not use mod_evhost or mod_simple_vhost with IPv6 address-style host names (i.e., '[...]' bracket notation in Host header), as these can be used to traverse directories.
  • Monitor HTTP requests where the Host header contains '..' sequences; these are the attack payloads for CVE-2014-2324 against lighttpd mod_evhost and mod_simple_vhost.
  • ·Vulnerability only affects lighttpd instances using mod_evhost or mod_simple_vhost modules; deployments not using these virtual hosting modules are not affected.
  • ·A workaround (short of patching) is to disable the affected virtual host modules entirely.
  • ·Fix is available in lighttpd 1.4.35 and backported Debian packages (1.4.33-1+nmu3); ensure the patched version is deployed.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.