CVE-2008-4298: Medium severity fipsasp fipscms light vulnerability
Published Sep 27, 2008
·Updated
Memory leak in the httprequestparse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
Affected Software
54 affected components
Lighttpd Lighttpd=1.4.3
Lighttpd Lighttpd=1.2.3
Lighttpd Lighttpd=1.2.5
Lighttpd Lighttpd=1.4.18
Lighttpd Lighttpd=1.3.6
Lighttpd Lighttpd=1.3.12
Lighttpd Lighttpd=1.3.15
Lighttpd Lighttpd=1.4.1
Lighttpd Lighttpd=1.2.2
Lighttpd Lighttpd=1.3.0
Lighttpd Lighttpd<=1.4.19
Lighttpd Lighttpd=1.4.8
Lighttpd Lighttpd=1.1.6
Lighttpd Lighttpd=1.4.17
Lighttpd Lighttpd=1.4.4
Lighttpd Lighttpd=1.1.5
Lighttpd Lighttpd=1.3.9
Lighttpd Lighttpd=1.2.4
Lighttpd Lighttpd=1.3.5
Lighttpd Lighttpd=1.1.1
Lighttpd Lighttpd=1.2.8
Lighttpd Lighttpd=1.3.13
Lighttpd Lighttpd=1.2.6
Lighttpd Lighttpd=1.3.4
Lighttpd Lighttpd=1.4.11
Lighttpd Lighttpd=1.4.2
Lighttpd Lighttpd=1.2.1
Lighttpd Lighttpd=1.3.14
Lighttpd Lighttpd=1.1.4
Lighttpd Lighttpd=1.1.9
Lighttpd Lighttpd=1.4.14
Lighttpd Lighttpd=1.4.10
Lighttpd Lighttpd=1.1.3
Lighttpd Lighttpd=1.4.5
Lighttpd Lighttpd=1.3.3
Lighttpd Lighttpd=1.4.16
Lighttpd Lighttpd=1.3.8
Lighttpd Lighttpd=1.1.7
Lighttpd Lighttpd=1.1.8
Lighttpd Lighttpd=1.3.11
Lighttpd Lighttpd=1.3.16
Lighttpd Lighttpd=1.3.1
Lighttpd Lighttpd=1.4.12
Lighttpd Lighttpd=1.4.9
Lighttpd Lighttpd=1.3.10
Lighttpd Lighttpd=1.1.2
Lighttpd Lighttpd=1.4.7
Lighttpd Lighttpd=1.4.6
Lighttpd Lighttpd=1.2.7
Lighttpd Lighttpd=1.4.15
Lighttpd Lighttpd=1.3.7
Lighttpd Lighttpd=1.4.13
Lighttpd Lighttpd=1.3.2
Lighttpd Lighttpd=1.4.0
Remediation
Patch Available
Event History
Sep 27, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4298?
CVE-2008-4298 has a medium severity level as it allows denial of service through memory consumption.
2
How do I fix CVE-2008-4298?
To fix CVE-2008-4298, upgrade to lighttpd version 1.4.20 or later.
3
What vulnerability does CVE-2008-4298 address?
CVE-2008-4298 addresses a memory leak in the http_request_parse function in lighttpd.
4
Which versions of lighttpd are affected by CVE-2008-4298?
CVE-2008-4298 affects lighttpd versions prior to 1.4.20, including all 1.1.x versions up to 1.4.19.
5
What impact does CVE-2008-4298 have on a system?
CVE-2008-4298 can lead to denial of service as a result of increased memory consumption from numerous requests with duplicate headers.