All errata/p7/ALT-PU-2013-1104-1
ALT-PU-2013-1104-1

Package update lighttpd in branch p7

Version1.4.33-alt1
Published2013-11-13
Max severityHIGH
Severity:

Closed issues (3)

CVE-2012-5533
MEDIUM5.0

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.

Published: 2012-11-24Modified: 2026-04-29
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
References