MEDIUM
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function
Published Dec 3, 2018
6.7
MEDIUMCVSS 3.0
EPSS 0.43%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.