Total vulnerabilities in the database
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
Software | From | Fixed in |
---|---|---|
lighttpd / lighttpd | - | 1.4.50 |
suse / suse_linux_enterprise_server | 11-sp3 | 11-sp3.x |
opensuse / leap | 15.0 | 15.0.x |
suse / suse_linux_enterprise_server | 11-sp4 | 11-sp4.x |
suse / suse_linux_enterprise_server | 12-sp3 | 12-sp3.x |
suse / suse_linux_enterprise_server | 12 | 12.x |
suse / suse_linux_enterprise_server | 12-sp1 | 12-sp1.x |
suse / suse_linux_enterprise_server | 12-sp2 | 12-sp2.x |
suse / suse_linux_enterprise_server | 12-sp4 | 12-sp4.x |
opensuse / leap | 15.1 | 15.1.x |
opensuse / backports_sle | 15.0-sp1 | 15.0-sp1.x |
opensuse / backports_sle | 15.0 | 15.0.x |
debian / debian_linux | 9.0 | 9.0.x |