MEDIUM
lighttpd: Remote DoS (excessive memory use) by handling specially-crafted HTTP request
Published Feb 3, 2010
5.0
MEDIUMCVSS 2.0
EPSS 12.11%
Description
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.
Affected products
No data.
OR
- ≤ 1.4.25
- 1.0.2
- 1.0.3
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
- 1.1.9
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.5
- 1.2.6
- 1.2.7
- 1.2.8
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.5
- 1.3.6
- 1.3.8
- 1.3.9
- 1.3.10
- 1.3.11
- 1.3.12
- 1.3.13
- 1.3.14
- 1.3.15
- 1.3.16
- 1.4.0
- 1.4.2
- 1.4.3
- 1.4.4
- 1.4.5
- 1.4.6
- 1.4.7
- 1.4.8
- 1.4.9
- 1.4.10
- 1.4.11
- 1.4.12
- 1.4.13
- 1.4.14
- 1.4.15
- 1.4.16
- 1.4.17
- 1.4.18
- 1.4.19
- 1.4.20
- 1.4.21
- 1.4.22
- 1.4.23
- 1.4.24
- 1.5.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (24)
- http://blogs.sun.com/security/entry/cve_2010_0295_vulnerability_in x_refsource_CONFIRM
- http://download.lighttpd.net/lighttpd/security/lighttpd-1.4.x_fix_slow_request_dos.patch x_refsource_CONFIRMPatch
- http://download.lighttpd.net/lighttpd/security/lighttpd-1.5_fix_slow_request_dos.patch x_refsource_CONFIRMPatch
- http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2010_01.txt x_refsource_CONFIRMPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041264.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041296.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041307.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html vendor-advisoryx_refsource_SUSE
- http://redmine.lighttpd.net/issues/2147 x_refsource_CONFIRM
- http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2710 x_refsource_CONFIRM
- http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2711 x_refsource_CONFIRM
- http://secunia.com/advisories/38403 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/39765 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201006-17.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2010/dsa-1987 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2010/02/01/8 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/38036 vdb-entryx_refsource_BIDExploitPatch
- http://www.vupen.com/english/advisories/2011/0172 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-0295 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=561340 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-0326 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56038 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-0295
- https://www.cve.org/CVERecord?id=CVE-2010-0295
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 3, 2010
Updated Aug 7, 2024
Reserved Jan 12, 2010
Link CVE-2010-0295
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-0326 Assigner redhat
Published Feb 3, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-0326