CVE-2010-0295: Medium severity Lighttpd Lighttpd vulnerability
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0295?
CVE-2010-0295 has a severity rating that indicates it can allow for denial of service through excessive memory consumption.
How do I fix CVE-2010-0295?
To fix CVE-2010-0295, users should update to Lighttpd version 1.4.26 or later.
What versions of Lighttpd are affected by CVE-2010-0295?
CVE-2010-0295 affects Lighttpd versions before 1.4.26 and the entire 1.5.x series.
What is the exploit method for CVE-2010-0295?
The exploit method for CVE-2010-0295 involves remote attackers breaking requests into small pieces and sending them at a slow rate.
Can CVE-2010-0295 lead to server outages?
Yes, CVE-2010-0295 can lead to server outages due to denial of service caused by excessive memory usage.