CVE-2014-2324
published 2014-03-14CVE-2014-2324: Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary…
PriorityP340medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
28.81%
97.9th percentile
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| contec | sv-cpt-mc310_firmware | < 6.5 | 6.5 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | lighttpd | < lighttpd 1.4.33-1+nmu3 (bookworm) | lighttpd 1.4.33-1+nmu3 (bookworm) |
| lighttpd | lighttpd | < 1.4.35 | 1.4.35 |
| lighttpd | lighttpd | >= 0 < 1.4.33-1+nmu3 | 1.4.33-1+nmu3 |
| lighttpd | lighttpd | >= 0 < 1.4.33-1+nmu3 | 1.4.33-1+nmu3 |
| lighttpd | lighttpd | >= 0 < 1.4.33-1+nmu3 | 1.4.33-1+nmu3 |
| lighttpd | lighttpd | >= 0 < 1.4.33-1+nmu3 | 1.4.33-1+nmu3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_high_availability_extension | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Directory traversal attack vector: attacker places '..' (dot dot) sequences in the HTTP Host header, exploiting mod_evhost or mod_simple_vhost to read arbitrary files outside the web root. ↗
- →Specifically, do not use mod_evhost or mod_simple_vhost with IPv6 address-style host names (i.e., '[...]' bracket notation in Host header), as these can be used to traverse directories. ↗
- →Monitor HTTP requests where the Host header contains '..' sequences; these are the attack payloads for CVE-2014-2324 against lighttpd mod_evhost and mod_simple_vhost. ↗
- ·Vulnerability only affects lighttpd instances using mod_evhost or mod_simple_vhost modules; deployments not using these virtual hosting modules are not affected. ↗
- ·A workaround (short of patching) is to disable the affected virtual host modules entirely. ↗
- ·Fix is available in lighttpd 1.4.35 and backported Debian packages (1.4.33-1+nmu3); ensure the patched version is deployed. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-2324: lighttpd - Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simpl...
vendor_debian·2014·CVSS 5.0
CVE-2014-2324 [MEDIUM] CVE-2014-2324: lighttpd - Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simpl...
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
Scope: local
bookworm: resolved (fixed in 1.4.33-1+nmu3)
bullseye: resolved (fixed in 1.4.33-1+nmu3)
forky: resolved (fixed in 1.4.33-1+nmu3)
sid: resolved (fixed in 1.4.33-1+nmu3)
trixie: resolved (fixed in 1.4.33-1+nmu3)
GHSA
GHSA-mvq4-g5jc-x2wr: Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1
ghsa_unreviewed·2022-05-13
CVE-2014-2324 [MEDIUM] CWE-22 GHSA-mvq4-g5jc-x2wr: Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
OSV
CVE-2014-2324: Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1
osv·2014-03-14·CVSS 5.0
CVE-2014-2324 [MEDIUM] CVE-2014-2324: Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2324 CVE-2014-2323 lighttpd: SQL injection and directory traversal vulnerabilities [fedora-all]
bugzilla·2014-03-12·CVSS 9.8
CVE-2014-2324 [CRITICAL] CVE-2014-2324 CVE-2014-2323 lighttpd: SQL injection and directory traversal vulnerabilities [fedora-all]
CVE-2014-2324 CVE-2014-2323 lighttpd: SQL injection and directory traversal vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2014-2324 CVE-2014-2323 lighttpd: SQL injection and directory traversal vulnerabilities [epel-all]
bugzilla·2014-03-12·CVSS 9.8
CVE-2014-2324 [CRITICAL] CVE-2014-2324 CVE-2014-2323 lighttpd: SQL injection and directory traversal vulnerabilities [epel-all]
CVE-2014-2324 CVE-2014-2323 lighttpd: SQL injection and directory traversal vulnerabilities [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
Bugzilla
CVE-2014-2323 CVE-2014-2324 lighttpd: SQL injection and directory traversal vulnerabilities
bugzilla·2014-03-12·CVSS 9.8
CVE-2014-2323 [CRITICAL] CVE-2014-2323 CVE-2014-2324 lighttpd: SQL injection and directory traversal vulnerabilities
CVE-2014-2323 CVE-2014-2324 lighttpd: SQL injection and directory traversal vulnerabilities
It was reported [1] that lighttpd's mod_mysql_vhost module is vulnerable to SQL injection attacks (CVE-2014-2323), and the mod_evhost or mod_simple_vhost modules are vulnerable to directory traversal attacks (CVE-2014-2324). More information can be found at [2].
This issue has been fixed in version 1.4.35 of lighttpd [3], and the patch is available at [4].
A workaround for this issue exists:
* Disable the mod_mysql_vhost module.
* Do not use the mod_evhost or mod_simple_vhost modules for IPv6 addresses as host names (i.e. don't have and don't allow creation of "[...]" directories in the base directories).
[1] http://seclists.org/oss-sec/2014/q1/561
[2] http://download.lighttpd.net/lighttpd/secu
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2014_01.txthttp://jvn.jp/en/jp/JVN37417423/index.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00006.htmlhttp://marc.info/?l=bugtraq&m=141576815022399&w=2http://seclists.org/oss-sec/2014/q1/561http://seclists.org/oss-sec/2014/q1/564http://secunia.com/advisories/57404http://secunia.com/advisories/57514http://www.debian.org/security/2014/dsa-2877http://www.lighttpd.net/2014/3/12/1.4.35/http://www.securityfocus.com/bid/66157http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2014_01.txthttp://jvn.jp/en/jp/JVN37417423/index.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00006.htmlhttp://marc.info/?l=bugtraq&m=141576815022399&w=2http://seclists.org/oss-sec/2014/q1/561http://seclists.org/oss-sec/2014/q1/564http://secunia.com/advisories/57404http://secunia.com/advisories/57514http://www.debian.org/security/2014/dsa-2877http://www.lighttpd.net/2014/3/12/1.4.35/http://www.securityfocus.com/bid/66157
2014-03-14
Published