CVE Vulnerabilities

CVE-2007-1869

Published: Apr 18, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.

Affected Software

NameVendorStart VersionEnd Version
LighttpdLighttpd1.4.12 (including)1.4.12 (including)
LighttpdLighttpd1.4.13 (including)1.4.13 (including)
LighttpdUbuntudevel*
LighttpdUbuntuedgy*
LighttpdUbuntufeisty*
LighttpdUbuntugutsy*

References