CVE Vulnerabilities

CVE-2008-0983

Published: Feb 26, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.

Affected Software

NameVendorStart VersionEnd Version
LighttpdLighttpd1.4.7 (including)1.4.7 (including)
LighttpdLighttpd1.4.8 (including)1.4.8 (including)
LighttpdLighttpd1.4.9 (including)1.4.9 (including)
LighttpdLighttpd1.4.10 (including)1.4.10 (including)
LighttpdLighttpd1.4.11 (including)1.4.11 (including)
LighttpdLighttpd1.4.12 (including)1.4.12 (including)
LighttpdLighttpd1.4.13 (including)1.4.13 (including)
LighttpdLighttpd1.4.14 (including)1.4.14 (including)
LighttpdLighttpd1.4.15 (including)1.4.15 (including)
LighttpdLighttpd1.4.16 (including)1.4.16 (including)
LighttpdLighttpd1.4.17 (including)1.4.17 (including)
LighttpdLighttpd1.4.18 (including)1.4.18 (including)
LighttpdUbuntudapper*
LighttpdUbuntudevel*
LighttpdUbuntuedgy*
LighttpdUbuntufeisty*
LighttpdUbuntugutsy*
LighttpdUbuntuupstream*

References