Description: A vulnerability has been reported in lighttpd, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to a calculation error when allocating the global file descriptor array and can be exploited to crash an affected server.
The vulnerability is reported in version 1.4.18. Other versions may also be affected.
Solution: Update to version 1.4.19.
Provided and/or discovered by: fdeletang
Changelog: 2008-02-28: Added CVE reference.
2008-03-11: Updated "Solution" section, added new link to the "Original Advisory" section.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.