Lighttpd File Descriptor Array Remote Denial of Service Vulnerability
BID:27943
Info
Lighttpd File Descriptor Array Remote Denial of Service Vulnerability
| Bugtraq ID: | 27943 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-0983 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2008 12:00AM |
| Updated: | Apr 13 2015 09:42PM |
| Credit: | fdeletang reported this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise SDK 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 rPath rPath Linux 1 Redhat Fedora 7 lighttpd lighttpd 1.4.18 lighttpd lighttpd 1.4.17 lighttpd lighttpd 1.4.16 lighttpd lighttpd 1.4.15 lighttpd lighttpd 1.4.14 lighttpd lighttpd 1.4.13 lighttpd lighttpd 1.4.12 lighttpd lighttpd 1.4.11 lighttpd lighttpd 1.4.10 lighttpd lighttpd 1.4.9 lighttpd lighttpd 1.4.8 lighttpd lighttpd 1.4.7 lighttpd lighttpd 1.4.6 lighttpd lighttpd 1.4.5 lighttpd lighttpd 1.4.4 lighttpd lighttpd 1.4.3 lighttpd lighttpd 1.4.2 lighttpd lighttpd 1.4.1 lighttpd lighttpd 1.4 lighttpd lighttpd 1.4.10a Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Lighttpd File Descriptor Array Remote Denial of Service Vulnerability
The 'lighttpd' program is prone to a remote denial-of-service vulnerability because it fails to handle exceptional conditions.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.
The issue affects lighttpd 1.4.18; other versions may also be vulnerable.
The 'lighttpd' program is prone to a remote denial-of-service vulnerability because it fails to handle exceptional conditions.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.
The issue affects lighttpd 1.4.18; other versions may also be vulnerable.
Exploit / POC
Lighttpd File Descriptor Array Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Lighttpd File Descriptor Array Remote Denial of Service Vulnerability
Solution:
The vendor has released a temporary patch to address this issue.
Please see the references and contact the vendor for information on obtaining the final fix.
lighttpd lighttpd 1.4.18
Solution:
The vendor has released a temporary patch to address this issue.
Please see the references and contact the vendor for information on obtaining the final fix.
lighttpd lighttpd 1.4.18
-
lighttpd Fix-372-and-1562.patch
http://trac.lighttpd.net/trac/attachment/ticket/1562/Fix-372-and-1562. patch
References
Lighttpd File Descriptor Array Remote Denial of Service Vulnerability
References:
References: