Описание
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
Релиз | Статус | Примечание |
---|---|---|
bionic | not-affected | code not present |
devel | not-affected | 1.4.67-1ubuntu2 |
esm-apps/bionic | not-affected | code not present |
esm-apps/focal | not-affected | code not present |
esm-apps/jammy | released | 1.4.63-1ubuntu3.1 |
esm-apps/noble | not-affected | 1.4.67-1ubuntu2 |
esm-apps/xenial | not-affected | code not present |
esm-infra-legacy/trusty | needs-triage | |
focal | not-affected | code not present |
jammy | released | 1.4.63-1ubuntu3.1 |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 coul ...
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
EPSS
7.5 High
CVSS3