CVE-2018-19791: Input Validation
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the entire response body repeatedly, as demonstrated by an HTTP Range header value beginning with the "bytes=0-,0-" substring.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19791?
CVE-2018-19791 is a vulnerability in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 that allows attackers to amplify response size by requesting the entire response body repeatedly.
How severe is CVE-2018-19791?
The severity of CVE-2018-19791 is rated as medium with a CVSS score of 6.5.
What software versions are affected by CVE-2018-19791?
LiteSpeed OpenLiteSpeed versions up to 1.5.0, including 1.5.0-rc1, 1.5.0-rc2, 1.5.0-rc3, 1.5.0-rc4, and 1.5.0-rc5 are affected by CVE-2018-19791.
How can I mitigate CVE-2018-19791?
To mitigate CVE-2018-19791, users should update LiteSpeed OpenLiteSpeed to version 1.5.0 RC6 or later.