Vulnerability Bulletins |
DSA-4142 uwsgi - security update |
|
| Affected software | Debian |
|
Marios Nicolaides discovered that the PHP plugin in uWSGI, a fast,self-healing application container server, does not properly handle aDOCUMENT_ROOT check during use of the --php-docroot option, allowing aremote attacker to mount a directory traversal attack and gainunauthorized read access to sensitive files located outside of the webroot directory. More info: https://www.debian.org/security/2018/dsa-4142 |
|






