CVE-2018-19792: Litespeedtech Openlitespeed

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function.

Affected products

  • Litespeedtech Openlitespeed: up to and including 1.4.41; version 1.5.0 only

Published 2018-12-03. Last modified 2026-06-17.