5
CVSSv2

CVE-2008-0983

Published: 26/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

lighttpd 1.4.18, and possibly other versions prior to 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote malicious users to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.

Vulnerable Product Search on Vulmon Subscribe to Product

lighttpd lighttpd 1.4.16

lighttpd lighttpd 1.4.17

lighttpd lighttpd 1.4.10

lighttpd lighttpd 1.4.11

lighttpd lighttpd 1.4.18

lighttpd lighttpd 1.4.7

lighttpd lighttpd 1.4.14

lighttpd lighttpd 1.4.15

lighttpd lighttpd 1.4.12

lighttpd lighttpd 1.4.13

lighttpd lighttpd 1.4.8

lighttpd lighttpd 1.4.9

Vendor Advisories

Several local/remote vulnerabilities have been discovered in lighttpd, a fast webserver with minimal memory footprint The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-0983 lighttpd 1418, and possibly other versions before 150, does not properly calculate the size of a file descriptor array, whic ...