|
|
| |
|
| |
lighttpd: denial of service
| Package(s): | lighttpd |
CVE #(s): | CVE-2010-0295
|
| Created: | February 2, 2010 |
Updated: | June 3, 2010 |
| Description: |
From the Debian advisory:
Li Ming discovered that lighttpd, a small and fast webserver with minimal
memory footprint, is vulnerable to a denial of service attack due to bad
memory handling. Slowly sending very small chunks of request data causes
lighttpd to allocate new buffers for each read instead of appending to
old ones. An attacker can abuse this behaviour to cause denial of service
conditions due to memory exhaustion.
|
| Alerts: |
|
( Log in to post comments)
|
|
|