Input validation error in lighttpd - CVE-2007-1869

 

Input validation error in lighttpd - CVE-2007-1869

Published: April 18, 2007 / Updated: August 4, 2020


Vulnerability identifier: #VU33827
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2007-1869
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.


Affected software

lighttpd
Gentoo Linux
lighttpd (Alpine package)

How to mitigate CVE-2007-1869

Install update from vendor's website.

lighttpd - update to 1.4.13
lighttpd (Alpine package) - update to 1.4.35-r4

External References

Related Security Bulletins