CVE-2008-1531
published 2008-03-27CVE-2008-1531: The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.37%
87.4th percentile
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | lighttpd | < lighttpd 1.4.19-2 (bookworm) | lighttpd 1.4.19-2 (bookworm) |
| lighttpd | lighttpd | <= 1.4.19 | — |
| lighttpd | lighttpd | >= 0 < 1.4.19-2 | 1.4.19-2 |
| lighttpd | lighttpd | >= 0 < 1.4.19-2 | 1.4.19-2 |
| lighttpd | lighttpd | >= 0 < 1.4.19-2 | 1.4.19-2 |
| lighttpd | lighttpd | >= 0 < 1.4.19-2 | 1.4.19-2 |
| lighttpd | lighttpd | >= 1.5 < 1.5.0 | 1.5.0 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2p48-prhc-qmgx: The connection_state_machine function (connections
ghsa_unreviewed·2022-05-01
CVE-2008-1531 [MEDIUM] GHSA-2p48-prhc-qmgx: The connection_state_machine function (connections
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
OSV
CVE-2008-1531: The connection_state_machine function (connections
osv·2008-03-27·CVSS 4.3
CVE-2008-1531 [MEDIUM] CVE-2008-1531: The connection_state_machine function (connections
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
Debian
CVE-2008-1531: lighttpd - The connection_state_machine function (connections.c) in lighttpd 1.4.19 and ear...
vendor_debian·2008·CVSS 4.3
CVE-2008-1531 [MEDIUM] CVE-2008-1531: lighttpd - The connection_state_machine function (connections.c) in lighttpd 1.4.19 and ear...
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
Scope: local
bookworm: resolved (fixed in 1.4.19-2)
bullseye: resolved (fixed in 1.4.19-2)
forky: resolved (fixed in 1.4.19-2)
sid: resolved (fixed in 1.4.19-2)
trixie: resolved (fixed in 1.4.19-2)
Red Hat
lighttpd closes unrelated SSL connections on SSL error
vendor_redhat·CVSS 4.3
CVE-2008-1531 [MEDIUM] lighttpd closes unrelated SSL connections on SSL error
lighttpd closes unrelated SSL connections on SSL error
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.htmlhttp://secunia.com/advisories/29505http://secunia.com/advisories/29544http://secunia.com/advisories/29636http://secunia.com/advisories/29649http://secunia.com/advisories/30023http://security.gentoo.org/glsa/glsa-200804-08.xmlhttp://trac.lighttpd.net/trac/changeset/2136http://trac.lighttpd.net/trac/changeset/2139http://trac.lighttpd.net/trac/changeset/2140http://trac.lighttpd.net/trac/ticket/285#comment:18http://trac.lighttpd.net/trac/ticket/285#comment:21http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0132http://www.debian.org/security/2008/dsa-1540http://www.osvdb.org/43788http://www.securityfocus.com/archive/1/490323/100/0/threadedhttp://www.securityfocus.com/bid/28489http://www.vupen.com/english/advisories/2008/1063/referenceshttps://bugs.gentoo.org/show_bug.cgi?id=214892https://exchange.xforce.ibmcloud.com/vulnerabilities/41545https://issues.rpath.com/browse/RPL-2407https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00562.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00587.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.htmlhttp://secunia.com/advisories/29505http://secunia.com/advisories/29544http://secunia.com/advisories/29636http://secunia.com/advisories/29649http://secunia.com/advisories/30023http://security.gentoo.org/glsa/glsa-200804-08.xmlhttp://trac.lighttpd.net/trac/changeset/2136http://trac.lighttpd.net/trac/changeset/2139http://trac.lighttpd.net/trac/changeset/2140http://trac.lighttpd.net/trac/ticket/285#comment:18http://trac.lighttpd.net/trac/ticket/285#comment:21http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0132http://www.debian.org/security/2008/dsa-1540http://www.osvdb.org/43788http://www.securityfocus.com/archive/1/490323/100/0/threadedhttp://www.securityfocus.com/bid/28489http://www.vupen.com/english/advisories/2008/1063/referenceshttps://bugs.gentoo.org/show_bug.cgi?id=214892https://exchange.xforce.ibmcloud.com/vulnerabilities/41545https://issues.rpath.com/browse/RPL-2407https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00562.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00587.html
2008-03-27
Published