oss-sec mailing list archives
Re: CVE request: lighttpd DoS: forcefully closing of foreign SSL connections
From: "Steven M. Christey" <coley () linus mitre org>
Date: Mon, 31 Mar 2008 17:10:06 -0400 (EDT)
On Fri, 28 Mar 2008, Christian Hoffmann wrote:
Just for reference, apparently CVE-2008-1531 has been assigned to this issue, thanks to whoever did it. :)
You requested it, guess I forgot to respond to the list once I took care of it? - Steve ====================================================== Name: CVE-2008-1531 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1531 Reference: CONFIRM:http://trac.lighttpd.net/trac/ticket/285#comment:18 Reference: CONFIRM:http://trac.lighttpd.net/trac/changeset/2136 Reference: CONFIRM:https://bugs.gentoo.org/show_bug.cgi?id=214892 lighttpd 1.4.19 and earlier allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
Current thread:
- CVE request: lighttpd DoS: forcefully closing of foreign SSL connections Christian Hoffmann (Mar 26)
- Re: CVE request: lighttpd DoS: forcefully closing of foreign SSL connections Christian Hoffmann (Mar 28)
- Re: CVE request: lighttpd DoS: forcefully closing of foreign SSL connections Steven M. Christey (Mar 31)
- Re: CVE request: lighttpd DoS: forcefully closing of foreign SSL connections Christian Hoffmann (Mar 28)