Security Advisory

CVE-2013-1427

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-03-21 17:00:00
Last updated 2024-08-06 15:04:48
Assigner debian
CVSS score not scored
State PUBLISHED

Description

The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.