New User, Welcome!     Login

Li Ming

[SECURITY] [DSA 1987-1] New lighttpd packages fix denial of service

Problem type   : remote
Debian-specific: no
Debian bug     : none
CVE ID         : CVE-2010-0295

Li Ming discovered that lighttpd, a small and fast webserver with minimal
memory footprint, is vulnerable to a denial of service attack due to bad
memory handling.  Slowly sending very small chunks of request data causes
lighttpd to allocate new buffers for each read instead of appending to
old ones.  An attacker can abuse this behaviour to cause denial of service
conditions due to memory exhaustion.

[ GLSA 201006-17 ] lighttpd: Denial of Service

  1  www-servers/lighttpd      < 1.4.25-r1                >= 1.4.25-r1

Description
===========

Li Ming reported that lighttpd does not properly process packets that
are sent overly slow.

Impact
======




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!