4.3
CVSSv2

CVE-2008-1531

Published: 27/03/2008 Updated: 31/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The connection_state_machine function (connections.c) in lighttpd 1.4.19 and previous versions, and 1.5.x prior to 1.5.0, allows remote malicious users to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lighttpd lighttpd

debian debian linux 4.0

Vendor Advisories

Debian Bug report logs - #475438 lighttpd: CVE-2008-1531 SSL connection loss can be triggered by SSL errors Package: lighttpd; Maintainer for lighttpd is Debian QA Group <packages@qadebianorg>; Source for lighttpd is src:lighttpd (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 10 Apr 2008 ...
It was discovered that lighttpd, a fast webserver with minimal memory footprint, didn't correctly handle SSL errors This could allow a remote attacker to disconnect all active SSL connections For the stable distribution (etch), this problem has been fixed in version 1413-4etch7 We recommend that you upgrade your lighttpd package ...