CVE-2012-5533: Medium severity fipsasp fipscms light vulnerability
Published Nov 24, 2012
·Updated
The httprequestsplitvalue function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.
Affected Software
2 affected components
Lighttpd Lighttpd=1.4.31
Lighttpd Lighttpd=1.4.32
Remediation
Event History
Nov 24, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5533?
CVE-2012-5533 is classified as a denial of service vulnerability.
2
How do I fix CVE-2012-5533?
To fix CVE-2012-5533, upgrade to lighttpd version 1.4.32 or later.
3
What vulnerabilities are associated with CVE-2012-5533?
CVE-2012-5533 allows remote attackers to cause an infinite loop through malformed HTTP headers.
4
Is CVE-2012-5533 present in lighttpd version 1.4.31?
Yes, CVE-2012-5533 is present in lighttpd version 1.4.31.
5
What is the impact of CVE-2012-5533 on web servers?
The impact of CVE-2012-5533 on web servers is that it can lead to denial of service, rendering the server unresponsive.