cbcvebase.
CVE-2008-1531
published 2008-03-27

CVE-2008-1531: The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of…

PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.37%
87.4th percentile
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlighttpd< lighttpd 1.4.19-2 (bookworm)lighttpd 1.4.19-2 (bookworm)
lighttpdlighttpd<= 1.4.19
lighttpdlighttpd>= 0 < 1.4.19-21.4.19-2
lighttpdlighttpd>= 0 < 1.4.19-21.4.19-2
lighttpdlighttpd>= 0 < 1.4.19-21.4.19-2
lighttpdlighttpd>= 0 < 1.4.19-21.4.19-2
lighttpdlighttpd>= 1.5 < 1.5.01.5.0

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.