CVE-2014-2324
EPSS 28.8%
描述
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
如何修補 CVE-2014-2324
要修補 CVE-2014-2324,請將受影響套件升級到下列已修補版本。
- Debian/lighttpd—升級至 1.4.33-1+nmu3 或更新版本
CVE-2014-2324 正在被利用嗎?
中等 — EPSS 為 28.8%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 1.4.33-1+nmu3