The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lighttpd | Jul 30, 2024 | Mar 27, 2008 |
| Freebsd | — | Upgrade lighttpd | Dec 10, 2025 | Apr 13, 2008 |
| Gentoo Linux | — | Upgrade www-servers/lighttpd. | Oct 30, 2017 | Mar 27, 2008 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Dec 8, 2014 | Mar 27, 2008 |
| Suse | — | Upgrade lighttpd-mod_mysql_vhostUpgrade lighttpdUpgrade lighttpd-mod_cmlUpgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpd-mod_webdavUpgrade lighttpd-mod_rrdtoolUpgrade lighttpd-mod_magnet | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade lighttpd | Nov 19, 2024 | Mar 27, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub