CVE-2007-4727
CVE-2007-4727
Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPT_FILENAME variable, aka a "header overflow."
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://fedoranews.org/updates/FEDORA-2007-213.shtmlhttps://bugzilla.redhat.com/show_bug.cgi?id=284511http://secunia.com/advisories/26732http://secunia.com/advisories/26794http://secunia.com/advisories/26824http://secunia.com/advisories/26997http://secunia.com/advisories/27229http://securityreason.com/securityalert/3127http://secweb.se/en/advisories/lighttpd-fastcgi-remote-vulnerability/https://exchange.xforce.ibmcloud.com/vulnerabilities/36526https://issues.rpath.com/browse/RPL-1715http://trac.lighttpd.net/trac/changeset/1986