Vulnerability Name:

CVE-2008-0983 (CCN-40779)

Assigned:2008-02-13
Published:2008-02-13
Updated:2018-10-15
Summary:lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2008-0983

Source: SUSE
Type: UNKNOWN
SUSE-SR:2008:008

Source: CCN
Type: SA29066
lighttpd File Descriptor Array Denial of Service Vulnerability

Source: SECUNIA
Type: Patch, Vendor Advisory
29066

Source: SECUNIA
Type: UNKNOWN
29166

Source: SECUNIA
Type: UNKNOWN
29209

Source: SECUNIA
Type: UNKNOWN
29268

Source: SECUNIA
Type: UNKNOWN
29622

Source: SECUNIA
Type: UNKNOWN
31104

Source: GENTOO
Type: UNKNOWN
GLSA-200803-10

Source: CCN
Type: lighttpd Web site: Ticket #1562
sigsegv @ fdevent_get_handler - when congestion occurs, and file descriptor arrays is full

Source: CONFIRM
Type: Patch
http://trac.lighttpd.net/trac/ticket/1562

Source: CONFIRM
Type: UNKNOWN
http://wiki.rpath.com/Advisories:rPSA-2008-0084

Source: DEBIAN
Type: UNKNOWN
DSA-1609

Source: DEBIAN
Type: DSA-1609
lighttpd -- various

Source: CCN
Type: GLSA-200803-10
lighttpd: Multiple vulnerabilities

Source: CCN
Type: lighttpd Web site
lighttpd fly light

Source: CCN
Type: OSVDB ID: 42363
lighttpd File Descriptor Array Connection Saturation Remote DoS

Source: BUGTRAQ
Type: UNKNOWN
20080228 rPSA-2008-0084-1 lighttpd

Source: BID
Type: Patch
27943

Source: CCN
Type: BID-27943
Lighttpd File Descriptor Array Remote Denial of Service Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2008-0659

Source: XF
Type: UNKNOWN
lighttpd-file-descriptor-dos(40779)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-2284

Source: FEDORA
Type: UNKNOWN
FEDORA-2008-2262

Source: FEDORA
Type: UNKNOWN
FEDORA-2008-2278

Source: SUSE
Type: SUSE-SR:2008:008
SUSE Security Summary Advisory

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lighttpd:lighttpd:1.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.9:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.10:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.11:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.12:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.13:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.14:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.15:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.16:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.17:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.18:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:lighttpd:lighttpd:1.4.18:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20080983
    V
    CVE-2008-0983
    2022-06-30
    oval:org.opensuse.security:def:112949
    P
    lighttpd-1.4.59-2.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106403
    P
    lighttpd-1.4.59-2.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:26137
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:26073
    P
    Security update for libjpeg-turbo (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:36512
    P
    lighttpd-1.4.20-2.54.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26062
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:26061
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:26740
    P
    libarchive2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27475
    P
    libpulse-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26487
    P
    Security update for redis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26779
    P
    logwatch on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26265
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:27510
    P
    lighttpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26638
    P
    squid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26793
    P
    openswan on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26346
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26691
    P
    enscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26837
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26403
    P
    Security update for ffmpeg (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:8187
    P
    DSA-1609 lighttpd -- various
    2014-06-23
    oval:org.mitre.oval:def:20065
    P
    DSA-1609-1 lighttpd - multiple DOS issues
    2014-06-23
    oval:org.debian:def:1609
    V
    various
    2008-07-15
    BACK
    lighttpd lighttpd 1.4.7
    lighttpd lighttpd 1.4.8
    lighttpd lighttpd 1.4.9
    lighttpd lighttpd 1.4.10
    lighttpd lighttpd 1.4.11
    lighttpd lighttpd 1.4.12
    lighttpd lighttpd 1.4.13
    lighttpd lighttpd 1.4.14
    lighttpd lighttpd 1.4.15
    lighttpd lighttpd 1.4.16
    lighttpd lighttpd 1.4.17
    lighttpd lighttpd 1.4.18
    lighttpd lighttpd 1.4.18
    gentoo linux *
    debian debian linux 4.0