5
CVSSv2

CVE-2010-0295

Published: 03/02/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

lighttpd prior to 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote malicious users to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lighttpd lighttpd 1.4.18

lighttpd lighttpd 1.4.2

lighttpd lighttpd 1.4.9

lighttpd lighttpd 1.4.19

lighttpd lighttpd 1.4.5

lighttpd lighttpd 1.4.6

lighttpd lighttpd 1.4.14

lighttpd lighttpd 1.4.13

lighttpd lighttpd 1.3.6

lighttpd lighttpd 1.3.5

lighttpd lighttpd 1.3.13

lighttpd lighttpd 1.3.12

lighttpd lighttpd 1.2.5

lighttpd lighttpd 1.2.3

lighttpd lighttpd 1.1.6

lighttpd lighttpd 1.1.5

lighttpd lighttpd 1.0.2

lighttpd lighttpd 1.4.20

lighttpd lighttpd 1.4.10

lighttpd lighttpd 1.4.0

lighttpd lighttpd 1.3.2

lighttpd lighttpd 1.3.16

lighttpd lighttpd 1.3.1

lighttpd lighttpd 1.3.0

lighttpd lighttpd 1.2.8

lighttpd lighttpd 1.2.0

lighttpd lighttpd 1.1.9

lighttpd lighttpd 1.1.2

lighttpd lighttpd 1.1.1

lighttpd lighttpd 1.4.23

lighttpd lighttpd 1.4.24

lighttpd lighttpd

lighttpd lighttpd 1.4.3

lighttpd lighttpd 1.4.4

lighttpd lighttpd 1.4.17

lighttpd lighttpd 1.4.16

lighttpd lighttpd 1.4.15

lighttpd lighttpd 1.3.9

lighttpd lighttpd 1.3.8

lighttpd lighttpd 1.3.15

lighttpd lighttpd 1.3.14

lighttpd lighttpd 1.2.7

lighttpd lighttpd 1.2.6

lighttpd lighttpd 1.1.8

lighttpd lighttpd 1.1.7

lighttpd lighttpd 1.1.0

lighttpd lighttpd 1.0.3

lighttpd lighttpd 1.5.0

lighttpd lighttpd 1.4.7

lighttpd lighttpd 1.4.8

lighttpd lighttpd 1.4.12

lighttpd lighttpd 1.4.11

lighttpd lighttpd 1.3.4

lighttpd lighttpd 1.3.3

lighttpd lighttpd 1.3.11

lighttpd lighttpd 1.3.10

lighttpd lighttpd 1.2.2

lighttpd lighttpd 1.2.1

lighttpd lighttpd 1.1.4

lighttpd lighttpd 1.1.3

lighttpd lighttpd 1.4.21

lighttpd lighttpd 1.4.22

Vendor Advisories

Li Ming discovered that lighttpd, a small and fast webserver with minimal memory footprint, is vulnerable to a denial of service attack due to bad memory handling Slowly sending very small chunks of request data causes lighttpd to allocate new buffers for each read instead of appending to old ones An attacker can abuse this behaviour to cause den ...

Exploits

source: wwwsecurityfocuscom/bid/38036/info The 'lighttpd' webserver is prone to a denial-of-service vulnerability Remote attackers can exploit this issue to cause the application to hang, denying service to legitimate users ##slow_testsh for ((j=0;j<1000;j++)) do for ((i=0; i<50; i++)) do ## slow_client is a C program whic ...