Vulnerabilities > CVE-2012-5533 - Resource Management Errors vulnerability in Lighttpd 1.4.31/1.4.32
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.
Common Weakness Enumeration (CWE)
NASL family Amazon Linux Local Security Checks NASL id ALA_ALAS-2013-179.NASL description The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the
NASL family SuSE Local Security Checks NASL id OPENSUSE-2012-801.NASL description - Fixing bnc#790258 CVE-2012-5533: Denial of Service via specially crafted HTTP header. Added patches: 0001-Fix-DoS-in-header-value-split-reported-by-Jesse-Sip p.patch 0001-remove-whitespace-at-end-of-header-keys.patch

NASL family Gentoo Local Security Checks NASL id GENTOO_GLSA-201406-10.NASL description The remote host is affected by the vulnerability described in GLSA-201406-10 (lighttpd: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in lighttpd. Please review the CVE identifiers referenced below for details. Impact : A remote attacker could create a Denial of Service condition. Futhermore, a remote attacker may be able to execute arbitrary SQL statements. Workaround : There is no known workaround at this time.

NASL family Web Servers NASL id LIGHTTPD_1_4_32.NASL description According to its banner, the version of lighttpd running on the remote host is 1.4.31. It is, therefore, affected by a denial of service vulnerability. An error in the http_request_split_value() function in

NASL family Fedora Local Security Checks NASL id FEDORA_2013-15344.NASL description One important denial of service (in 1.4.31) fix: CVE-2012-5533. A flaw was found in lighttpd version 1.4.31 that could be exploited by a remote user to cause a denial of service condition in lighttpd. A client could send a malformed Connection header to lighttpd (such as

NASL family Fedora Local Security Checks NASL id FEDORA_2013-15345.NASL description One important denial of service (in 1.4.31) fix: CVE-2012-5533. A flaw was found in lighttpd version 1.4.31 that could be exploited by a remote user to cause a denial of service condition in lighttpd. A client could send a malformed Connection header to lighttpd (such as

NASL family FreeBSD Local Security Checks NASL id FREEBSD_PKG_1CD3CA4233E611E2A2555404A67EEF98.NASL description Lighttpd security advisory reports : Certain Connection header values will trigger an endless loop, for example :

NASL family Mandriva Local Security Checks NASL id MANDRIVA_MDVSA-2013-100.NASL description The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the Connection: TE,,Keep-Alive header (CVE-2012-5533).
