CVE-2013-4559

lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.


We have discovered 2,122 live websites that are affected by CVE-2013-4559.

Run a Free Instant Scan




Affected Software

Product  lighttpd
Category Web Servers
Vulnerable Domains2,122 live websites (4.35% of lighttpd install base)
Vulnerable Versions
  • from 0 through 1.4.33
Vulnerable Versions Count14 versions ( 24% of all versions)



Details

  • Published - Nov 19, 2013
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2013-4559
United States288 websites



France792 websites
Czech Republic188 websites
Germany170 websites
Singapore108 websites
GB75 websites
Poland58 websites
India50 websites
Italy45 websites
Russia45 websites

Website Distribution by TLD

Number of websites using CVE-2013-4559
.com522 websites
.fr492 websites
.net307 websites
.cz142 websites
.de99 websites
.org96 websites
.ru42 websites
.eu31 websites
.nl27 websites
.pl26 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2013-4559

Top websites that are affected by CVE-2013-4559. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.****.cz Czech Republic**,***
********.com United States***,***
***.*********.com United States***,***
*****.net United States***,***
*********.********.pm United States***,***
***.****.fr France***,***
*************.********.pm United States***,***
***.cz Czech Republic***,***
********.net Singapore***,***
*****.**************.de Germany***,***
See full domain list

FAQ

A total of 2,122 websites have been identified as vulnerable to CVE-2013-4559, based on global website indexing conducted by WebTechSurvey.
The lighttpd is affected by the CVE-2013-4559 vulnerability.
lighttpd versions up to and including 1.4.33 are vulnerable to CVE-2013-4559.