Lighttpd SSL Error Denial of Service Vulnerability
BID:28489
Info
Lighttpd SSL Error Denial of Service Vulnerability
| Bugtraq ID: | 28489 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1531 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2008 12:00AM |
| Updated: | Jul 24 2008 12:08AM |
| Credit: | Marton Illes |
| Vulnerable: |
S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux Enterprise Server 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc rPath rPath Linux 1 Red Hat Fedora 9 Red Hat Fedora 8 Red Hat Fedora 7 lighttpd lighttpd 1.4.19 lighttpd lighttpd 1.4.18 lighttpd lighttpd 1.4.17 lighttpd lighttpd 1.4.16 lighttpd lighttpd 1.4.15 lighttpd lighttpd 1.4.14 lighttpd lighttpd 1.4.13 lighttpd lighttpd 1.4.12 lighttpd lighttpd 1.4.11 lighttpd lighttpd 1.4.10 lighttpd lighttpd 1.4.9 lighttpd lighttpd 1.4.8 lighttpd lighttpd 1.4.7 lighttpd lighttpd 1.4.6 lighttpd lighttpd 1.4.5 lighttpd lighttpd 1.4.4 lighttpd lighttpd 1.4.3 lighttpd lighttpd 1.4.2 lighttpd lighttpd 1.4.1 lighttpd lighttpd 1.4 lighttpd lighttpd 1.4.10a Gentoo Linux 2007.0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Lighttpd SSL Error Denial of Service Vulnerability
The 'lighttpd' program is prone to a remote denial-of-service vulnerability because it fails to handle exceptional conditions.
Successfully exploiting this issue allows remote attackers to close foreign SSL connections, denying service to legitimate users.
The issue affects lighttpd 1.4.19 and prior versions.
The 'lighttpd' program is prone to a remote denial-of-service vulnerability because it fails to handle exceptional conditions.
Successfully exploiting this issue allows remote attackers to close foreign SSL connections, denying service to legitimate users.
The issue affects lighttpd 1.4.19 and prior versions.
Exploit / POC
Lighttpd SSL Error Denial of Service Vulnerability
Attacker can use a browser to exploit this issue.
Attacker can use a browser to exploit this issue.
Solution / Fix
Lighttpd SSL Error Denial of Service Vulnerability
Solution:
A fix is available in the SVN repository. Please see the references and contact the vendor for information on obtaining and applying the fix.
Solution:
A fix is available in the SVN repository. Please see the references and contact the vendor for information on obtaining and applying the fix.
References
Lighttpd SSL Error Denial of Service Vulnerability
References:
References:
- Gentoo Bug 214892 (Gentoo)
- lighttpd Changeset 2136 (lighttpd)
- lighttpd Homepage (lighttpd)
- Ticket #285 (reopened defect) (lighttpd)