>> Lighttpd "connection_state_machine()" Denial of Service Vulnerability
Title : Lighttpd "connection_state_machine()" Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-1063 CVE ID : CVE-2008-1531
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-02
Technical Description
A vulnerability has been identified in Lighttpd, which could be exploited by attackers to cause a denial of service. This issue is caused by an error in the "connection_state_machine()" [src/connections.c] function when terminating SSL connections, which could be exploited by a remote attacker to cause all active SSL connections to be lost by triggering an SSL error (e.g. disconnecting before a download has finished).