Computer Security
[EN] securityvulns.ru no-pyccku


liggttpd multiple denial of service conditions
Published:19.04.2007
Source:
SecurityVulns ID:7603
Type:remote
Threat Level:
6/10
Description:NULL pointer dereference, infinite loop.
Affected:LIGHTTPD : lighttpd 1.4
CVE:CVE-2007-1870 (lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointer dereference.)
 CVE-2007-1869 (lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod