PT-2008-3090 · Lighttpd · Lighttpd

Publicado

2008-03-27

·

Atualizado

2024-06-15

·

CVE-2008-1531

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions lighttpd versions 1.4.19 and earlier lighttpd versions 1.5.x before 1.5.0
Description The issue allows remote attackers to cause a denial of service, specifically an active SSL connection loss, by triggering an SSL error. This can occur when an action such as disconnecting before a download has finished is performed, resulting in the loss of all active SSL connections.
Recommendations For lighttpd versions 1.4.19 and earlier, update to a version later than 1.4.19. For lighttpd versions 1.5.x before 1.5.0, update to version 1.5.0 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2008-1531
DSA-1540-1
OPENSUSE-SU-2024:10585-1

Produtos afetados

Lighttpd