CVE Vulnerabilities

CVE-2007-1869

Published: Apr 18, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.

Affected Software

Name Vendor Start Version End Version
Lighttpd Lighttpd 1.4.12 (including) 1.4.12 (including)
Lighttpd Lighttpd 1.4.13 (including) 1.4.13 (including)
Lighttpd Ubuntu devel *
Lighttpd Ubuntu edgy *
Lighttpd Ubuntu feisty *
Lighttpd Ubuntu gutsy *

References