CVE-2012-5533

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 24 Nov 2012, 20:00
Last modified:06 Aug 2024, 21:05

Vulnerability Summary

Overall Risk (default)
medium
38/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
37.91% HIGH
38% probability -4.78%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

24 Nov 2012, 20:00
Published
Vulnerability first disclosed
06 Aug 2024, 21:05
Last Modified
Vulnerability information updated

Description

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 37.91% Percentile: 97%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • lighttpdlighttpd

    1.4.31 | 1.4.32

References (16)