Описание
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 1.4.11-3ubuntu3.5 |
devel | not-affected | |
edgy | released | 1.4.13~r1370-1ubuntu1.3 |
feisty | released | 1.4.13-9ubuntu4.2 |
gutsy | not-affected | |
upstream | released | 1.4.16 |
Показывать по
Ссылки на источники
6.4 Medium
CVSS2
Связанные уязвимости
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attacke ...
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.
6.4 Medium
CVSS2