Lucene search

K
freebsdFreeBSD1AC77649-0908-11DD-974D-000FEA2763CE
HistoryApr 02, 2008 - 12:00 a.m.

lighttpd -- OpenSSL Error Queue Denial of Service Vulnerability

2008-04-0200:00:00
vuxml.freebsd.org
12

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.1

Percentile

95.0%

Secunia reports:

A vulnerability has been reported in lighttpd, which can be
exploited by malicious people to cause a DoS (Denial of
Service).
The vulnerability is caused due to lighttpd not properly clearing
the OpenSSL error queue. This can be exploited to close concurrent
SSL connections of lighttpd by terminating one SSL connection.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchlighttpd< 1.4.19_1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.1

Percentile

95.0%