CVE-2007-1869: Medium severity Lighttpd Lighttpd vulnerability
Published Apr 18, 2007
·Updated
lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.
Affected Software
2 affected components
Lighttpd Lighttpd=1.4.12
Lighttpd Lighttpd=1.4.13
Remediation
Event History
Apr 18, 2007
CVE Published
03:19 AM
CVE Published
via MITRE·06:20 AM
Data Sourced
via MITRE·06:20 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1869?
The severity of CVE-2007-1869 is considered high due to its potential to cause denial of service through resource exhaustion.
2
How do I fix CVE-2007-1869?
To fix CVE-2007-1869, upgrade to lighttpd version 1.4.14 or later, which addresses this vulnerability.
3
What types of systems are affected by CVE-2007-1869?
CVE-2007-1869 affects lighttpd versions 1.4.12 and 1.4.13.
4
What kind of attack does CVE-2007-1869 enable?
CVE-2007-1869 enables remote denial of service attacks by causing CPU and resource exhaustion.
5
Can CVE-2007-1869 affect server availability?
Yes, CVE-2007-1869 can significantly impact server availability due to its infinite loop and file descriptor consumption.