Vulnerability Name:

CVE-2012-5533 (CCN-80213)

Assigned:2012-11-22
Published:2012-11-22
Updated:2017-08-29
Summary:The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.
Per: http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2012_01.txt

" Affected versions
-------------------

Only 1.4.31; on the other hand versions before 1.4.31 include the "invalid read" bug."
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2012-5533

Source: MISC
Type: Patch
http://download.lighttpd.net/lighttpd/security/lighttpd-1.4.31_fix_connection_header_dos.patch

Source: CONFIRM
Type: Vendor Advisory
http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2012_01.txt

Source: CCN
Type: lighttpd Web site
lighttpd

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2012:1532

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2014:0074

Source: HP
Type: UNKNOWN
HPSBGN03191

Source: OSVDB
Type: UNKNOWN
87623

Source: CCN
Type: Packetstorm Security Website
Simple Lighttpd 1.4.31 Denial Of Service

Source: MISC
Type: UNKNOWN
http://packetstormsecurity.org/files/118282/Simple-Lighttpd-1.4.31-Denial-Of-Service.html

Source: CCN
Type: SA51268
lighttpd HTTP Header Processing Denial of Service Vulnerability

Source: SECUNIA
Type: Vendor Advisory
51268

Source: SECUNIA
Type: Vendor Advisory
51298

Source: EXPLOIT-DB
Type: Exploit
22902

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2013:100

Source: MLIST
Type: UNKNOWN
[oss-security] 20121121 lighttpd 1.4.32 released, fixing CVE-2012-5533

Source: CCN
Type: OSVDB ID: 87623
lighttpd src/request.c http_request_split_value() Function Connection HTTP Header Handling Remote DoS

Source: BID
Type: Exploit
56619

Source: CCN
Type: BID-56619
lighttpd 'http_request_split_value()' Function Remote Denial of Service Vulnerability

Source: SECTRACK
Type: UNKNOWN
1027802

Source: XF
Type: UNKNOWN
lighttpd-httprequestsplitvalue-dos(80213)

Source: XF
Type: UNKNOWN
lighttpd-httprequestsplitvalue-dos(80213)

Source: CONFIRM
Type: UNKNOWN
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0345

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [11-22-2012]

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lighttpd:lighttpd:1.4.31:*:*:*:*:*:*:*
  • OR cpe:/a:lighttpd:lighttpd:1.4.32:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:lighttpd:lighttpd:1.4.31:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20125533
    V
    CVE-2012-5533
    2022-09-02
    oval:org.opensuse.security:def:6349
    P
    Security update for libgda (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:6327
    P
    Security update for the Linux Kernel (Important)
    2022-04-14
    oval:org.opensuse.security:def:6326
    P
    Security update for netatalk (Important)
    2022-04-13
    oval:org.opensuse.security:def:6361
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:6337
    P
    Security update for polkit (Important)
    2022-01-25
    oval:org.opensuse.security:def:6304
    P
    Security update for clamav-database (Important)
    2022-01-17
    oval:org.opensuse.security:def:112948
    P
    lighttpd-1.4.37-1.6 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:6293
    P
    Security update for virglrenderer (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:6296
    P
    Security update for net-snmp (Important)
    2022-01-11
    oval:org.opensuse.security:def:6285
    P
    Security update for clamav-database (Important)
    2022-01-03
    oval:org.opensuse.security:def:7288
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:6307
    P
    Security update for the Linux Kernel (Important)
    2021-11-19
    oval:org.opensuse.security:def:7278
    P
    Security update for the Linux Kernel (Important)
    2021-11-11
    oval:org.opensuse.security:def:6457
    P
    Security update for the Linux Kernel (Important)
    2021-10-15
    oval:org.opensuse.security:def:7277
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:106402
    P
    lighttpd-1.4.37-1.6 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:7266
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP3) (Important)
    2021-09-16
    oval:org.opensuse.security:def:6453
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:6476
    P
    Security update for the Linux Kernel (Important)
    2021-08-14
    oval:org.opensuse.security:def:7255
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:123991
    P
    lighttpd-1.4.35-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12785
    P
    lighttpd-1.4.35-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12796
    P
    lighttpd-1.4.35-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12774
    P
    lighttpd-1.4.35-1.34 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:6445
    P
    Security update for the Linux Kernel (Important)
    2021-04-16
    oval:org.opensuse.security:def:7244
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP2) (Important)
    2021-03-17
    oval:org.opensuse.security:def:6319
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:6464
    P
    Security update for java-1_8_0-ibm (Important)
    2021-03-01
    oval:org.opensuse.security:def:6315
    P
    Security update for avahi (Moderate)
    2021-02-23
    oval:org.opensuse.security:def:6442
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:12808
    P
    lighttpd-1.4.35-3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:6423
    P
    libpython2_7-1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6372
    P
    libexif12 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6615
    P
    gnome-keyring on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6609
    P
    gdm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6542
    P
    yast2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7300
    P
    lighttpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6419
    P
    libpoppler-glib8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6640
    P
    imobiledevice-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6618
    P
    gnome-shell on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6575
    P
    ctags on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6528
    P
    wget on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6434
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6383
    P
    libgypsy0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6627
    P
    gstreamer-0_10-plugins-good on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6584
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6553
    P
    apparmor-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6430
    P
    libsilc-1_1-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6593
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6586
    P
    dnsmasq on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6539
    P
    xorg-x11-libs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6395
    P
    libldap-2_4-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6617
    P
    gnome-settings-daemon on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6595
    P
    eog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6564
    P
    busybox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6604
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6597
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6551
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6408
    P
    libneon27 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6628
    P
    gstreamer-plugins-bad on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6606
    P
    gd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6576
    P
    cups on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6517
    P
    tcpdump on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.precise:def:20125533000
    V
    CVE-2012-5533 on Ubuntu 12.04 LTS (precise) - medium.
    2012-11-24
    BACK
    lighttpd lighttpd 1.4.31
    lighttpd lighttpd 1.4.32
    lighttpd lighttpd 1.4.31