Memory Leak Vulnerability in Lighttpd Web Server
CVE-2008-4298

Currently unrated

Key Information:

Vendor

Lighttpd

Status
Vendor
CVE Published:
27 September 2008

What is CVE-2008-4298?

The vulnerability in Lighttpd arises from a memory leak in the http_request_parse function. Attackers can exploit this flaw by sending a high volume of requests that contain duplicate headers, leading to increased memory consumption and potentially resulting in a denial of service. This security concern affects versions of Lighttpd prior to 1.4.20, necessitating immediate attention from administrators to mitigate potential service disruptions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.