CVE-2008-1531

The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
lighttpdlighttpd
𝑥
≤ 1.4.19
lighttpdlighttpd
1.5 ≤
𝑥
< 1.5.0
debiandebian_linux
4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lighttpd
bullseye
1.4.59-1+deb11u2
fixed
bullseye (security)
1.4.59-1+deb11u2
fixed
bookworm
1.4.69-1
fixed
sid
1.4.76-1
fixed
trixie
1.4.76-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lighttpd
karmic
Fixed 1.4.19-0ubuntu3
released
jaunty
Fixed 1.4.19-0ubuntu3
released
intrepid
Fixed 1.4.19-0ubuntu3
released
hardy
Fixed 1.4.19-0ubuntu3
released
gutsy
Fixed 1.4.18-1ubuntu1.4
released
feisty
Fixed 1.4.13-9ubuntu4.6
released
edgy
Fixed 1.4.13~r1370-1ubuntu1.7
released
dapper
ignored
References