LWN.net Logo

lighttpd: denial of service

Package(s):lighttpd CVE #(s):CVE-2007-1869 CVE-2007-1870
Created:April 18, 2007 Updated:June 11, 2007
Description: lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption. (CVE-2007-1869)

lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointer dereference. (CVE-2007-1870)

Alerts:
Debian DSA-1303-1 2007-06-10
Gentoo 200705-07 2007-05-07
Foresight FLEA-2007-0011-1 2007-04-20
SuSE SUSE-SR:2007:007 2007-04-20
rPath rPSA-2007-0072-1 2007-04-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds