|
|

CVE Reference: CVE-2008-0983 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2008-0983 |
|
|
Description: lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access. |
|
|
CVE Status: Candidate |
|
|
References: SUSE http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html SAID Secunia Advisory: SA29066 Secunia Advisory: SA29166 Secunia Advisory: SA29209 Secunia Advisory: SA29268 Secunia Advisory: SA29622 Secunia Advisory: SA31104 GENTOO http://security.gentoo.org/glsa/glsa-200803-10.xml FEDORA DEBIAN http://www.debian.org/security/2008/dsa-1609 CONFIRM http://wiki.rpath.com/Advisories:rPSA-2008-0084 http://trac.lighttpd.net/trac/ticket/1562 BUGTRAQ http://www.securityfocus.com/archive/1/archive/1/488926/100/0/threaded BID 27943 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |