CVE-2018-19792
03.12.2018, 06:29
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function.Enginsight
Vendor | Product | Version |
---|---|---|
litespeedtech | openlitespeed | 𝑥 ≤ 1.4.41 |
litespeedtech | openlitespeed | 1.5.0:rc1 |
litespeedtech | openlitespeed | 1.5.0:rc2 |
litespeedtech | openlitespeed | 1.5.0:rc3 |
litespeedtech | openlitespeed | 1.5.0:rc4 |
litespeedtech | openlitespeed | 1.5.0:rc5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration