CVE-2008-0983
published 2008-02-26CVE-2008-0983: lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.31%
81.5th percentile
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lighttpd | < lighttpd 1.4.18-2 (bookworm) | lighttpd 1.4.18-2 (bookworm) |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | >= 0 < 1.4.18-2 | 1.4.18-2 |
| lighttpd | lighttpd | >= 0 < 1.4.18-2 | 1.4.18-2 |
| lighttpd | lighttpd | >= 0 < 1.4.18-2 | 1.4.18-2 |
| lighttpd | lighttpd | >= 0 < 1.4.18-2 | 1.4.18-2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2008-0983: lighttpd - lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly cal...
vendor_debian·2008·CVSS 5.0
CVE-2008-0983 [MEDIUM] CVE-2008-0983: lighttpd - lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly cal...
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
Scope: local
bookworm: resolved (fixed in 1.4.18-2)
bullseye: resolved (fixed in 1.4.18-2)
forky: resolved (fixed in 1.4.18-2)
sid: resolved (fixed in 1.4.18-2)
trixie: resolved (fixed in 1.4.18-2)
Red Hat
lighttpd crashes when it's low on file descriptors
vendor_redhat·CVSS 5.0
CVE-2008-0983 [MEDIUM] lighttpd crashes when it's low on file descriptors
lighttpd crashes when it's low on file descriptors
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
GHSA
GHSA-fxrf-v868-58jw: lighttpd 1
ghsa_unreviewed·2022-05-01
CVE-2008-0983 [MEDIUM] GHSA-fxrf-v868-58jw: lighttpd 1
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
OSV
CVE-2008-0983: lighttpd 1
osv·2008-02-26·CVSS 5.0
CVE-2008-0983 [MEDIUM] CVE-2008-0983: lighttpd 1
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/29066http://secunia.com/advisories/29166http://secunia.com/advisories/29209http://secunia.com/advisories/29268http://secunia.com/advisories/29622http://secunia.com/advisories/31104http://security.gentoo.org/glsa/glsa-200803-10.xmlhttp://trac.lighttpd.net/trac/ticket/1562http://wiki.rpath.com/Advisories:rPSA-2008-0084http://www.debian.org/security/2008/dsa-1609http://www.securityfocus.com/archive/1/488926/100/0/threadedhttp://www.securityfocus.com/bid/27943http://www.vupen.com/english/advisories/2008/0659/referenceshttps://issues.rpath.com/browse/RPL-2284https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00162.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00180.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlhttp://secunia.com/advisories/29066http://secunia.com/advisories/29166http://secunia.com/advisories/29209http://secunia.com/advisories/29268http://secunia.com/advisories/29622http://secunia.com/advisories/31104http://security.gentoo.org/glsa/glsa-200803-10.xmlhttp://trac.lighttpd.net/trac/ticket/1562http://wiki.rpath.com/Advisories:rPSA-2008-0084http://www.debian.org/security/2008/dsa-1609http://www.securityfocus.com/archive/1/488926/100/0/threadedhttp://www.securityfocus.com/bid/27943http://www.vupen.com/english/advisories/2008/0659/referenceshttps://issues.rpath.com/browse/RPL-2284https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00162.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00180.html
2008-02-26
Published