Debian Security Update DSA-4142 uwsgi - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,806
Reaction score
74
Credits
-1,257
Marios Nicolaides discovered that the PHP plugin in uWSGI, a fast, self-healing application container server, does not properly handle a DOCUMENT_ROOT check during use of the --php-docroot option, allowing a remote attacker to mount a directory traversal attack and gain unauthorized read access to sensitive files located outside of the web root directory.

Continue reading...
 


Follow Linux.org

Members online


Latest posts

Top