First published: Wed Apr 18 2007(Updated: )
lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipscms Light | =1.4.12 | |
Fipsasp Fipscms Light | =1.4.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-1869 is considered high due to its potential to cause denial of service through resource exhaustion.
To fix CVE-2007-1869, upgrade to lighttpd version 1.4.14 or later, which addresses this vulnerability.
CVE-2007-1869 affects lighttpd versions 1.4.12 and 1.4.13.
CVE-2007-1869 enables remote denial of service attacks by causing CPU and resource exhaustion.
Yes, CVE-2007-1869 can significantly impact server availability due to its infinite loop and file descriptor consumption.