The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
References
Information
Published : 2008-03-27 16:44
Updated : 2018-10-31 12:23
NVD link : CVE-2008-1531
Mitre link : CVE-2008-1531
JSON object : View
CWE
Products Affected
debian
- debian_linux
lighttpd
- lighttpd