The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the Connection: TE,,Keep-Alive header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lighttpd | Lighttpd | 1.4.31 (including) | 1.4.31 (including) |
Lighttpd | Lighttpd | 1.4.32 (including) | 1.4.32 (including) |
Lighttpd | Ubuntu | upstream | * |