CVE-2008-0983

lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
lighttpdlighttpd
1.4.7
lighttpdlighttpd
1.4.8
lighttpdlighttpd
1.4.9
lighttpdlighttpd
1.4.10
lighttpdlighttpd
1.4.11
lighttpdlighttpd
1.4.12
lighttpdlighttpd
1.4.13
lighttpdlighttpd
1.4.14
lighttpdlighttpd
1.4.15
lighttpdlighttpd
1.4.16
lighttpdlighttpd
1.4.17
lighttpdlighttpd
1.4.18
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lighttpd
bullseye (security)
1.4.59-1+deb11u2
fixed
bullseye
1.4.59-1+deb11u2
fixed
bookworm
1.4.69-1
fixed
sid
1.4.76-1
fixed
trixie
1.4.76-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lighttpd
gutsy
Fixed 1.4.18-1ubuntu1.1
released
feisty
Fixed 1.4.13-9ubuntu4.3
released
edgy
Fixed 1.4.13~r1370-1ubuntu1.4
released
dapper
Fixed 1.4.11-3ubuntu3.6
released
Common Weakness Enumeration
References