Back

MEDIUM

lighttpd closes unrelated SSL connections on SSL error

Published Mar 27, 2008

Description

The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 27, 2008
Updated Aug 7, 2024
Reserved Mar 27, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a