Vulnerability Name:

CVE-2013-4560 (CCN-88880)

Assigned:2013-11-12
Published:2013-11-12
Updated:2021-03-04
Summary:Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-416
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2013-4560

Source: CCN
Type: lighttpd SVN Repository Web Site
lighttpd SVN Repository

Source: CCN
Type: lighttpd Web site
Use after free if FAMMonitorDirectory fails

Source: CONFIRM
Type: Vendor Advisory
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_03.txt

Source: JVN
Type: Third Party Advisory
JVN#37417423

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2014:0072

Source: HP
Type: Mailing List, Third Party Advisory
HPSBGN03191

Source: CCN
Type: oss-sec Mailing List, Tue, 12 Nov 2013 11:13:14 -0700
Re: CVE Request: lighttpd multiple issues (setuid/... unchecked return value, FAM: read after free)

Source: SECUNIA
Type: Third Party Advisory
55682

Source: DEBIAN
Type: DSA-2795
lighttpd -- several vulnerabilities

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20131112 Re: CVE Request: lighttpd multiple issues (setuid/... unchecked return value, FAM: read after free)

Source: CCN
Type: BID-63686
lighttpd CVE-2013-4560 Use-After-Free Remote Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
lighttpd-cve20134560-dos(88880)

Source: DEBIAN
Type: Third Party Advisory
DSA-2795

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2013-4560

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lighttpd:lighttpd:*:*:*:*:*:*:*:* (Version < 1.4.33)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:lighttpd:lighttpd:1.4.31:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.33:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.32:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20134560
    V
    CVE-2013-4560
    2022-09-02
    oval:org.opensuse.security:def:6349
    P
    Security update for libgda (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:6327
    P
    Security update for the Linux Kernel (Important)
    2022-04-14
    oval:org.opensuse.security:def:6326
    P
    Security update for netatalk (Important)
    2022-04-13
    oval:org.opensuse.security:def:6361
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:6337
    P
    Security update for polkit (Important)
    2022-01-25
    oval:org.opensuse.security:def:112948
    P
    lighttpd-1.4.37-1.6 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:6304
    P
    Security update for clamav-database (Important)
    2022-01-17
    oval:org.opensuse.security:def:6293
    P
    Security update for virglrenderer (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:6296
    P
    Security update for net-snmp (Important)
    2022-01-11
    oval:org.opensuse.security:def:6285
    P
    Security update for clamav-database (Important)
    2022-01-03
    oval:org.opensuse.security:def:7288
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:6307
    P
    Security update for the Linux Kernel (Important)
    2021-11-19
    oval:org.opensuse.security:def:7278
    P
    Security update for the Linux Kernel (Important)
    2021-11-11
    oval:org.opensuse.security:def:6457
    P
    Security update for the Linux Kernel (Important)
    2021-10-15
    oval:org.opensuse.security:def:7277
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:106402
    P
    lighttpd-1.4.37-1.6 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:7266
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP3) (Important)
    2021-09-16
    oval:org.opensuse.security:def:6453
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:6476
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:7255
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:12774
    P
    lighttpd-1.4.35-1.34 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:123991
    P
    lighttpd-1.4.35-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12785
    P
    lighttpd-1.4.35-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12796
    P
    lighttpd-1.4.35-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:29363
    P
    Security update for djvulibre (Important)
    2021-05-19
    oval:org.opensuse.security:def:6445
    P
    Security update for the Linux Kernel (Important)
    2021-04-16
    oval:org.opensuse.security:def:26212
    P
    Security update for python3 (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:7244
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP2) (Important)
    2021-03-17
    oval:org.opensuse.security:def:6319
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:6464
    P
    Security update for java-1_8_0-ibm (Important)
    2021-03-01
    oval:org.opensuse.security:def:26201
    P
    Security update for java-1_8_0-ibm (Important)
    2021-02-26
    oval:org.opensuse.security:def:26200
    P
    Security update for glibc (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:6315
    P
    Security update for avahi (Moderate)
    2021-02-23
    oval:org.opensuse.security:def:6442
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:12808
    P
    lighttpd-1.4.35-3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:26276
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6539
    P
    xorg-x11-libs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29327
    P
    Security update for compat-openssl097g (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27906
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:6627
    P
    gstreamer-0_10-plugins-good on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28252
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6606
    P
    gd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26485
    P
    Security update for singularity (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6586
    P
    dnsmasq on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6542
    P
    yast2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28488
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6628
    P
    gstreamer-plugins-bad on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6593
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6430
    P
    libsilc-1_1-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28629
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:6372
    P
    libexif12 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26879
    P
    cvs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27981
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:6551
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26976
    P
    libtspi1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27905
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:6423
    P
    libpython2_7-1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6618
    P
    gnome-shell on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28195
    P
    Security update for libdb-4_5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6597
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26404
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6553
    P
    apparmor-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27649
    P
    Security update for lighttpd
    2020-12-01
    oval:org.opensuse.security:def:6517
    P
    tcpdump on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6640
    P
    imobiledevice-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26626
    P
    pam_mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6604
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6584
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6383
    P
    libgypsy0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28590
    P
    Security update for libfreebl3
    2020-12-01
    oval:org.opensuse.security:def:7300
    P
    lighttpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26830
    P
    t1lib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27917
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28689
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:6434
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26932
    P
    krb5-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6408
    P
    libneon27 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6609
    P
    gdm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28111
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6564
    P
    busybox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6528
    P
    wget on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27614
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:28336
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6615
    P
    gnome-keyring on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26542
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6595
    P
    eog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6395
    P
    libldap-2_4-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6575
    P
    ctags on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28541
    P
    Security update for dhcp
    2020-12-01
    oval:org.opensuse.security:def:26777
    P
    log4net on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6617
    P
    gnome-settings-daemon on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28645
    P
    Security update for compat-openssl097g
    2020-12-01
    oval:org.opensuse.security:def:6419
    P
    libpoppler-glib8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26918
    P
    ibutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6576
    P
    cups on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:28476
    P
    DSA-2795-2 -- lighttpd -- several vulnerabilities
    2015-08-17
    oval:org.mitre.oval:def:20141
    P
    DSA-2795-1 lighttpd - several
    2014-06-23
    oval:com.ubuntu.precise:def:20134560000
    V
    CVE-2013-4560 on Ubuntu 12.04 LTS (precise) - medium.
    2013-11-20
    oval:com.ubuntu.trusty:def:20134560000
    V
    CVE-2013-4560 on Ubuntu 14.04 LTS (trusty) - medium.
    2013-11-20
    oval:com.ubuntu.xenial:def:20134560000
    V
    CVE-2013-4560 on Ubuntu 16.04 LTS (xenial) - medium.
    2013-11-20
    oval:com.ubuntu.xenial:def:201345600000000
    V
    CVE-2013-4560 on Ubuntu 16.04 LTS (xenial) - medium.
    2013-11-20
    BACK
    lighttpd lighttpd *
    debian debian linux 6.0
    debian debian linux 7.0
    debian debian linux 8.0
    opensuse opensuse 12.2
    opensuse opensuse 12.3
    opensuse opensuse 13.1
    lighttpd lighttpd 1.4.31
    lighttpd lighttpd 1.4.33
    lighttpd lighttpd 1.4.32