Amazon Linux 1 Security Advisory: ALAS-2019-1265
Advisory Release Date: 2019-08-07 23:16 Pacific
Advisory Updated Date: 2024-09-13 01:16 Pacific
2024-09-13: CVE-2018-25103 was added to this advisory.
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character. (CVE-2018-19052)
There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests. (CVE-2018-25103)
Affected Packages:
lighttpd
Issue Correction:
Run yum update lighttpd to update your system.
i686:
lighttpd-fastcgi-1.4.53-1.36.amzn1.i686
lighttpd-debuginfo-1.4.53-1.36.amzn1.i686
lighttpd-mod_authn_pam-1.4.53-1.36.amzn1.i686
lighttpd-1.4.53-1.36.amzn1.i686
lighttpd-mod_mysql_vhost-1.4.53-1.36.amzn1.i686
lighttpd-mod_geoip-1.4.53-1.36.amzn1.i686
lighttpd-mod_authn_gssapi-1.4.53-1.36.amzn1.i686
lighttpd-mod_authn_mysql-1.4.53-1.36.amzn1.i686
src:
lighttpd-1.4.53-1.36.amzn1.src
x86_64:
lighttpd-1.4.53-1.36.amzn1.x86_64
lighttpd-mod_geoip-1.4.53-1.36.amzn1.x86_64
lighttpd-mod_authn_pam-1.4.53-1.36.amzn1.x86_64
lighttpd-mod_authn_gssapi-1.4.53-1.36.amzn1.x86_64
lighttpd-mod_mysql_vhost-1.4.53-1.36.amzn1.x86_64
lighttpd-debuginfo-1.4.53-1.36.amzn1.x86_64
lighttpd-fastcgi-1.4.53-1.36.amzn1.x86_64
lighttpd-mod_authn_mysql-1.4.53-1.36.amzn1.x86_64