Vulnerability Name:

CVE-2007-1869 (CCN-33671)

Assigned:2007-04-16
Published:2007-04-16
Updated:2018-10-16
Summary:lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2007-1869

Source: CCN
Type: lighttpd Web site
Lighttpd 1.4.15 - The "following traditions" release

Source: CCN
Type: SA24886
lighttpd "mtime" and "\r\n\r\n\" Denial of Service Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
24886

Source: SECUNIA
Type: UNKNOWN
24947

Source: SECUNIA
Type: UNKNOWN
24995

Source: SECUNIA
Type: UNKNOWN
25166

Source: SECUNIA
Type: UNKNOWN
25613

Source: GENTOO
Type: UNKNOWN
GLSA-200705-07

Source: DEBIAN
Type: UNKNOWN
DSA-1303

Source: DEBIAN
Type: DSA-1303
lighttpd -- denial of service

Source: CCN
Type: GLSA-200705-07
Lighttpd: Two Denials of Service

Source: CCN
Type: lighttpd.net Web site
Remote DOS in CRLF parsing

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_01.txt

Source: SUSE
Type: UNKNOWN
SUSE-SR:2007:007

Source: CCN
Type: OSVDB ID: 34175
lighttpd CRLF Processing DoS

Source: BUGTRAQ
Type: UNKNOWN
20070420 FLEA-2007-0011-1: lighttpd

Source: BID
Type: UNKNOWN
23515

Source: CCN
Type: BID-23515
Lighttpd Multiple Remote Denial of Service Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2007-1399

Source: XF
Type: UNKNOWN
lighttpd-rnrn-dos(33671)

Source: XF
Type: UNKNOWN
lighttpd-rnrn-dos(33671)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-1218

Source: SUSE
Type: SUSE-SR:2007:007
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lighttpd:lighttpd:1.4.12:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.13:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:lighttpd:lighttpd:1.4.12:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.13:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20071869
    V
    CVE-2007-1869
    2022-06-30
    oval:org.opensuse.security:def:112949
    P
    lighttpd-1.4.59-2.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106403
    P
    lighttpd-1.4.59-2.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:26137
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:26073
    P
    Security update for libjpeg-turbo (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:36512
    P
    lighttpd-1.4.20-2.54.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26062
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:26061
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:26779
    P
    logwatch on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26265
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:27510
    P
    lighttpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26638
    P
    squid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26793
    P
    openswan on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26346
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26691
    P
    enscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26837
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26403
    P
    Security update for ffmpeg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26740
    P
    libarchive2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27475
    P
    libpulse-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26487
    P
    Security update for redis (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:20327
    P
    DSA-1303-1 lighttpd - denial of service
    2014-06-23
    oval:org.debian:def:1303
    V
    denial of service
    2007-06-10
    BACK
    lighttpd lighttpd 1.4.12
    lighttpd lighttpd 1.4.13
    lighttpd lighttpd 1.4.12
    lighttpd lighttpd 1.4.13
    gentoo linux *
    debian debian linux 4.0