Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-5533

Опубликовано: 24 нояб. 2012
Источник: nvd
CVSS2: 5
EPSS Средний

Описание

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:lighttpd:lighttpd:1.4.31:*:*:*:*:*:*:*
cpe:2.3:a:lighttpd:lighttpd:1.4.32:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.39102
Средний

5 Medium

CVSS2

Дефекты

CWE-399

Связанные уязвимости

ubuntu
около 13 лет назад

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.

debian
около 13 лет назад

The http_request_split_value function in request.c in lighttpd before ...

github
больше 3 лет назад

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.

EPSS

Процентиль: 97%
0.39102
Средний

5 Medium

CVSS2

Дефекты

CWE-399