Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lighttpd 'request.c'远程拒绝服务攻击漏洞
Vulnerability Description
lighttpd是德国软件开发者Jan Kneschke所研发的一款开源的Web服务器,它的主要特点是仅需少量的内存及CPU资源即可达到同类网页服务器的性能。 lighttpd 1.4.15版本的request.c中存在远程拒绝服务攻击漏洞。Lighttpd没有正确地解析HTTP头,如果远程攻击者发送了包含有拖尾空格字符的特制HTTP请求的话,就可能导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A