CVE Vulnerabilities

CVE-2008-4298

Published: Sep 27, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.

Affected Software

Name Vendor Start Version End Version
Lighttpd Lighttpd * 1.4.19 (including)
Lighttpd Lighttpd 1.1.1 (including) 1.1.1 (including)
Lighttpd Lighttpd 1.1.2 (including) 1.1.2 (including)
Lighttpd Lighttpd 1.1.3 (including) 1.1.3 (including)
Lighttpd Lighttpd 1.1.4 (including) 1.1.4 (including)
Lighttpd Lighttpd 1.1.5 (including) 1.1.5 (including)
Lighttpd Lighttpd 1.1.6 (including) 1.1.6 (including)
Lighttpd Lighttpd 1.1.7 (including) 1.1.7 (including)
Lighttpd Lighttpd 1.1.8 (including) 1.1.8 (including)
Lighttpd Lighttpd 1.1.9 (including) 1.1.9 (including)
Lighttpd Lighttpd 1.2.1 (including) 1.2.1 (including)
Lighttpd Lighttpd 1.2.2 (including) 1.2.2 (including)
Lighttpd Lighttpd 1.2.3 (including) 1.2.3 (including)
Lighttpd Lighttpd 1.2.4 (including) 1.2.4 (including)
Lighttpd Lighttpd 1.2.5 (including) 1.2.5 (including)
Lighttpd Lighttpd 1.2.6 (including) 1.2.6 (including)
Lighttpd Lighttpd 1.2.7 (including) 1.2.7 (including)
Lighttpd Lighttpd 1.2.8 (including) 1.2.8 (including)
Lighttpd Lighttpd 1.3.0 (including) 1.3.0 (including)
Lighttpd Lighttpd 1.3.1 (including) 1.3.1 (including)
Lighttpd Lighttpd 1.3.2 (including) 1.3.2 (including)
Lighttpd Lighttpd 1.3.3 (including) 1.3.3 (including)
Lighttpd Lighttpd 1.3.4 (including) 1.3.4 (including)
Lighttpd Lighttpd 1.3.5 (including) 1.3.5 (including)
Lighttpd Lighttpd 1.3.6 (including) 1.3.6 (including)
Lighttpd Lighttpd 1.3.7 (including) 1.3.7 (including)
Lighttpd Lighttpd 1.3.8 (including) 1.3.8 (including)
Lighttpd Lighttpd 1.3.9 (including) 1.3.9 (including)
Lighttpd Lighttpd 1.3.10 (including) 1.3.10 (including)
Lighttpd Lighttpd 1.3.11 (including) 1.3.11 (including)
Lighttpd Lighttpd 1.3.12 (including) 1.3.12 (including)
Lighttpd Lighttpd 1.3.13 (including) 1.3.13 (including)
Lighttpd Lighttpd 1.3.14 (including) 1.3.14 (including)
Lighttpd Lighttpd 1.3.15 (including) 1.3.15 (including)
Lighttpd Lighttpd 1.3.16 (including) 1.3.16 (including)
Lighttpd Lighttpd 1.4.0 (including) 1.4.0 (including)
Lighttpd Lighttpd 1.4.1 (including) 1.4.1 (including)
Lighttpd Lighttpd 1.4.2 (including) 1.4.2 (including)
Lighttpd Lighttpd 1.4.3 (including) 1.4.3 (including)
Lighttpd Lighttpd 1.4.4 (including) 1.4.4 (including)
Lighttpd Lighttpd 1.4.5 (including) 1.4.5 (including)
Lighttpd Lighttpd 1.4.6 (including) 1.4.6 (including)
Lighttpd Lighttpd 1.4.7 (including) 1.4.7 (including)
Lighttpd Lighttpd 1.4.8 (including) 1.4.8 (including)
Lighttpd Lighttpd 1.4.9 (including) 1.4.9 (including)
Lighttpd Lighttpd 1.4.10 (including) 1.4.10 (including)
Lighttpd Lighttpd 1.4.11 (including) 1.4.11 (including)
Lighttpd Lighttpd 1.4.12 (including) 1.4.12 (including)
Lighttpd Lighttpd 1.4.13 (including) 1.4.13 (including)
Lighttpd Lighttpd 1.4.14 (including) 1.4.14 (including)
Lighttpd Lighttpd 1.4.15 (including) 1.4.15 (including)
Lighttpd Lighttpd 1.4.16 (including) 1.4.16 (including)
Lighttpd Lighttpd 1.4.17 (including) 1.4.17 (including)
Lighttpd Lighttpd 1.4.18 (including) 1.4.18 (including)

References