|
| Lighttpd multiple security vulnerabilities | | Published: |  | 17.08.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8066 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | Multiple memory corruption on request headers parsing. |
| Affected: |  | LIGHTHTTPD : lighttpd 1.4 | | CVE: |  | CVE-2007-3950 (lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules.) | | |  | CVE-2007-3949 (mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.) | | |  | CVE-2007-3948 (connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts.) | | |  | CVE-2007-3947 (request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.) | | |  | CVE-2007-3946 (mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.) |
|
|
|
|
|