lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lighttpd | Lighttpd | 1.4.12 (including) | 1.4.12 (including) |
Lighttpd | Lighttpd | 1.4.13 (including) | 1.4.13 (including) |
Lighttpd | Ubuntu | devel | * |
Lighttpd | Ubuntu | edgy | * |
Lighttpd | Ubuntu | feisty | * |
Lighttpd | Ubuntu | gutsy | * |