CVE-2008-4298
published 2008-09-27CVE-2008-4298: Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption)…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.53%
87.9th percentile
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lighttpd | < lighttpd 1.4.19-5 (bookworm) | lighttpd 1.4.19-5 (bookworm) |
| lighttpd | lighttpd | <= 1.4.19 | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
lighttpd: memory leak http_request_parse() in request.c
vendor_redhat·2008-09-20·CVSS 5.0
CVE-2008-4298 [MEDIUM] CWE-401 lighttpd: memory leak http_request_parse() in request.c
lighttpd: memory leak http_request_parse() in request.c
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
Debian
CVE-2008-4298: lighttpd - Memory leak in the http_request_parse function in request.c in lighttpd before 1...
vendor_debian·2008·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298: lighttpd - Memory leak in the http_request_parse function in request.c in lighttpd before 1...
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
Scope: local
bookworm: resolved (fixed in 1.4.19-5)
bullseye: resolved (fixed in 1.4.19-5)
forky: resolved (fixed in 1.4.19-5)
sid: resolved (fixed in 1.4.19-5)
trixie: resolved (fixed in 1.4.19-5)
GHSA
GHSA-w6pj-53xr-3hq6: Memory leak in the http_request_parse function in request
ghsa_unreviewed·2022-05-02
CVE-2008-4298 [MEDIUM] GHSA-w6pj-53xr-3hq6: Memory leak in the http_request_parse function in request
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
OSV
CVE-2008-4298: Memory leak in the http_request_parse function in request
osv·2008-09-27·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298: Memory leak in the http_request_parse function in request
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 8]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 8]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%208&bugs=464638,
---
New bodhi link:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%208&bugs=464638,CVE-2008-4298,CVE-2008-4359,CVE-2008-4360
---
This message is a reminder that Fedora 8 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 8. It is Fedora's policy to close all
bu
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-4]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-4]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-4]
epel-4 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
I had forgotten to close this report, doing so now.
Bugzilla
CVE-2008-4298 lighttpd: memory leak http_request_parse() in request.c
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 lighttpd: memory leak http_request_parse() in request.c
CVE-2008-4298 lighttpd: memory leak http_request_parse() in request.c
Memory leak in the http_request_parse function in request.c in
lighttpd before 1.4.20 allows remote attackers to cause a denial of
service (memory consumption) via a large number of requests with
duplicate request headers.
Reference: MLIST:[oss-security] 20080926 CVE Request (lighttpd)
Reference: URL:http://www.openwall.com/lists/oss-security/2008/09/26/5
Reference: CONFIRM:http://bugs.gentoo.org/show_bug.cgi?id=238180
Reference: CONFIRM:http://trac.lighttpd.net/trac/changeset/2305
Reference: CONFIRM:http://trac.lighttpd.net/trac/ticket/1774
Reference: CONFIRM:http://www.lighttpd.net/security/lighttpd_sa_2008_07.txt
Discussion:
lighttpd-1.4.20-6.fc9 has been submitted as an update for Fedora 9.
http://admin.fedorapro
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-5]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-5]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [epel-5]
epel-5 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
I had forgotten to close this report, doing so now.
Bugzilla
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 9]
bugzilla·2008-09-29·CVSS 5.0
CVE-2008-4298 [MEDIUM] CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 9]
CVE-2008-4298 CVE-2008-4359 CVE-2008-4360 lighttpd: multiple security issues [Fedora 9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=464639,
---
New bodhi link:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=464639,CVE-2008-4298,CVE-2008-4359,CVE-2008-4360
---
lighttpd-1.4.20-6.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/lighttpd-1.4.20-6.fc9
---
lighttpd-1.4.20-6.fc9 has been pushed to the Fedora 9 testing repository.
http://bugs.gentoo.org/show_bug.cgi?id=238180http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://secunia.com/advisories/32069http://secunia.com/advisories/32132http://secunia.com/advisories/32480http://secunia.com/advisories/32834http://secunia.com/advisories/32972http://security.gentoo.org/glsa/glsa-200812-04.xmlhttp://trac.lighttpd.net/trac/changeset/2305http://trac.lighttpd.net/trac/ticket/1774http://wiki.rpath.com/Advisories:rPSA-2008-0309http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309http://www.debian.org/security/2008/dsa-1645http://www.lighttpd.net/security/lighttpd_sa_2008_07.txthttp://www.openwall.com/lists/oss-security/2008/09/26/5http://www.securityfocus.com/archive/1/497932/100/0/threadedhttp://www.securityfocus.com/bid/31434http://www.vupen.com/english/advisories/2008/2741https://exchange.xforce.ibmcloud.com/vulnerabilities/45471http://bugs.gentoo.org/show_bug.cgi?id=238180http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://secunia.com/advisories/32069http://secunia.com/advisories/32132http://secunia.com/advisories/32480http://secunia.com/advisories/32834http://secunia.com/advisories/32972http://security.gentoo.org/glsa/glsa-200812-04.xmlhttp://trac.lighttpd.net/trac/changeset/2305http://trac.lighttpd.net/trac/ticket/1774http://wiki.rpath.com/Advisories:rPSA-2008-0309http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0309http://www.debian.org/security/2008/dsa-1645http://www.lighttpd.net/security/lighttpd_sa_2008_07.txthttp://www.openwall.com/lists/oss-security/2008/09/26/5http://www.securityfocus.com/archive/1/497932/100/0/threadedhttp://www.securityfocus.com/bid/31434http://www.vupen.com/english/advisories/2008/2741https://exchange.xforce.ibmcloud.com/vulnerabilities/45471
2008-09-27
Published