Lighttpd 'request.c' http_request_parse函数内存泄露漏洞

admin 2022-07-19 14:04:36 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

Lighttpd 'request.c' http_request_parse函数内存泄露漏洞

  • CNNVD编号:CNNVD-200809-396
  • 危害等级: 中危
  • CVE编号: CVE-2008-4298
  • 漏洞类型: 资源管理错误
  • 发布时间: 2008-09-27
  • 威胁类型: 远程
  • 更新时间: 2009-02-26
  • 厂        商: lighttpd
  • 漏洞来源: Reported by Gentoo

漏洞简介

lighttpd 1.4.20的之前版本的request.c的http_request_parse函数中存在内存漏洞。 远程攻击者可以通过提交具有请求页眉副本的多个请求来造成拒绝服务 (内存损耗)。

漏洞公告

"目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Debian Linux 4.0 arm

Debian lighttpd-doc_1.4.13-4etch11_all.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-doc_1

.4.13-4etch11_all.deb

Debian lighttpd-mod-cml_1.4.13-4etch11_arm.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-c

ml_1.4.13-4etch11_arm.deb

Debian lighttpd-mod-magnet_1.4.13-4etch11_arm.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m

agnet_1.4.13-4etch11_arm.deb

Debian lighttpd-mod-mysql-vhost_1.4.13-4etch11_arm.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m

ysql-vhost_1.4.13-4etch11_arm.deb

Debian lighttpd-mod-trigger-b4-dl_1.4.13-4etch11_arm.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-t

rigger-b4-dl_1.4.13-4etch11_arm.deb

Debian lighttpd-mod-webdav_1.4.13-4etch11_arm.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-w

ebdav_1.4.13-4etch11_arm.deb

Debian lighttpd_1.4.13-4etch11_arm.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd_1.4.1

3-4etch11_arm.deb

Debian Linux 4.0 powerpc

Debian lighttpd-doc_1.4.13-4etch11_all.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-doc_1

.4.13-4etch11_all.deb

Debian lighttpd-mod-cml_1.4.13-4etch11_powerpc.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-c

ml_1.4.13-4etch11_powerpc.deb

Debian lighttpd-mod-magnet_1.4.13-4etch11_powerpc.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m

agnet_1.4.13-4etch11_powerpc.deb

Debian lighttpd-mod-mysql-vhost_1.4.13-4etch11_powerpc.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m

ysql-vhost_1.4.13-4etch11_powerpc.deb

Debian lighttpd-mod-trigger-b4-dl_1.4.13-4etch11_powerpc.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-t

rigger-b4-dl_1.4.13-4etch11_powerpc.deb

Debian lighttpd-mod-webdav_1.4.13-4etch11_powerpc.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-w

ebdav_1.4.13-4etch11_powerpc.deb

Debian lighttpd_1.4.13-4etch11_powerpc.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd_1.4.1

3-4etch11_powerpc.deb

Debian Linux 4.0 m68k

Debian lighttpd-doc_1.4.13-4etch11_all.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-doc_1

.4.13-4etch11_all.deb

Debian Linux 4.0 amd64

Debian lighttpd-doc_1.4.13-4etch11_all.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-doc_1

.4.13-4etch11_all.deb

Debian lighttpd-mod-cml_1.4.13-4etch11_amd64.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-c

ml_1.4.13-4etch11_amd64.deb

Debian lighttpd-mod-magnet_1.4.13-4etch11_amd64.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m

agnet_1.4.13-4etch11_amd64.deb

Debian lighttpd-mod-mysql-vhost_1.4.13-4etch11_amd64.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m

ysql-vhost_1.4.13-4etch11_amd64.deb

Debian lighttpd-mod-trigger-b4-dl_1.4.13-4etch11_amd64.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-t

rigger-b4-dl_1.4.13-4etch11_amd64.deb

Debian lighttpd-mod-webdav_1.4.13-4etch11_amd64.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-w

ebdav_1.4.13-4etch11_amd64.deb

Debian lighttpd_1.4.13-4etch11_amd64.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd_1.4.1

3-4etch11_amd64.deb

Debian Linux 4.0 ia-32

Debian lighttpd-doc_1.4.13-4etch11_all.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-doc_1

.4.13-4etch11_all.deb

Debian lighttpd-mod-cml_1.4.13-4etch11_i386.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-c

ml_1.4.13-4etch11_i386.deb

Debian lighttpd-mod-magnet_1.4.13-4etch11_i386.deb

http://security.debian.org/pool/updates/main/l/lighttpd/lighttpd-mod-m

agnet_1.4.13-4etch11_i386.deb

Debian lighttpd-mod-mysql-vhost_1.4.13-4etch11_i386.deb

http://security.debian.org/pool/updates/mai

参考网址

来源: trac.lighttpd.net

链接:http://trac.lighttpd.net/trac/ticket/1774

来源: XF

名称: lighttpd-httprequestparse-dos(45471)

链接:http://xforce.iss.net/xforce/xfdb/45471

来源: BID

名称: 31434

链接:http://www.securityfocus.com/bid/31434

来源: BUGTRAQ

名称: 20081030 rPSA-2008-0309-1 lighttpd

链接:http://www.securityfocus.com/archive/1/archive/1/497932/100/0/threaded

来源: MLIST

名称: [oss-security] 20080926 CVE Request (lighttpd)

链接:http://www.openwall.com/lists/oss-security/2008/09/26/5

来源: www.lighttpd.net

链接:http://www.lighttpd.net/security/lighttpd_sa_2008_07.txt

来源: VUPEN

名称: ADV-2008-2741

链接:http://www.frsirt.com/english/advisories/2008/2741

来源: DEBIAN

名称: DSA-1645

链接:http://www.debian.org/security/2008/dsa-1645

来源: wiki.rpath.com

链接:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309

来源: wiki.rpath.com

链接:http://wiki.rpath.com/Advisories:rPSA-2008-0309

来源: trac.lighttpd.net

链接:http://trac.lighttpd.net/trac/changeset/2305

来源: GENTOO

名称: GLSA-200812-04

链接:http://security.gentoo.org/glsa/glsa-200812-04.xml

来源: SECUNIA

名称: 32972

链接:http://secunia.com/advisories/32972

来源: SECUNIA

名称: 32834

链接:http://secunia.com/advisories/32834

来源: SECUNIA

名称: 32480

链接:http://secunia.com/advisories/32480

来源: SECUNIA

名称: 32132

链接:http://secunia.com/advisories/32132

来源: SECUNIA

名称: 32069

链接:http://secunia.com/advisories/32069

来源: SUSE

名称: SUSE-SR:2008:026

链接:http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.HTML

来源: bugs.gentoo.org

链接:http://bugs.gentoo.org/show_bug.cgi?id=238180

受影响实体

  • Lighttpd Lighttpd:1.3.1  
  • Lighttpd Lighttpd:1.3.2  
  • Lighttpd Lighttpd:1.3.4  
  • Lighttpd Lighttpd:1.3.3  
  • Lighttpd Lighttpd:1.3.5  

补丁

    暂无

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
Cisco IOS 安全漏洞 CNNVD漏洞

Cisco IOS 安全漏洞

漏洞信息详情Cisco IOS 安全漏洞CNNVD编号:CNNVD-200809-375危害等级: 高危CVE编号:CVE-2008-3808漏洞类型:其他发布时间:2008-
评论:0   参与:  0