Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-3947Lighttpd vulnerability

6 documents6 sources
Severity
5.8MEDIUMNVD
EPSS
16.5%
top 5.08%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 24
Latest updateMay 1

Description

request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.

CVSS vector

AV:N/AC:M/C:P/I:N/A:PExploitability: 8.6 | Impact: 4.9

Affected Packages3 packages

debiandebian/lighttpd< lighttpd 1.4.16-1 (bookworm)
Debianlighttpd/lighttpd< 1.4.16-1+3
NVDlighttpd/lighttpd1.4.15

🔴Vulnerability Details

2
GHSA
GHSA-x97h-9f4h-rj28: request2022-05-01
OSV
CVE-2007-3947: request2007-07-24

💥Exploits & PoCs

1
Exploit-DB
Lighttpd 1.4.15 - Multiple Code Execution / Denial of Service / Information Disclosure Vulnerabilities2007-04-16

📋Vendor Advisories

1
Debian
CVE-2007-3947: lighttpd - request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of servic...2007

💬Community

1
Bugzilla
CVE-2007-394{6-9} lighttpd 1.4.15 multiple vulnerabilities2007-07-21