5
CVSSv2

CVE-2007-1869

Published: 18/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

lighttpd 1.4.12 and 1.4.13 allows remote malicious users to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lighttpd lighttpd 1.4.13

lighttpd lighttpd 1.4.12

Vendor Advisories

Debian Bug report logs - #422254 lighttpd: Security vulnerabilities in Etch version Package: lighttpd; Maintainer for lighttpd is Debian QA Group <packages@qadebianorg>; Source for lighttpd is src:lighttpd (PTS, buildd, popcon) Reported by: Jon Vaughan <jonathan-debianbugs@turniporguk> Date: Fri, 4 May 2007 14:1 ...
Two problems were discovered with lighttpd, a fast webserver with minimal memory footprint, which could allow denial of service The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1869 Remote attackers could cause denial of service by disconnecting partway through making a request CVE-2007-1870 A NU ...