lighttpd: Denial of Service A processing error in lighttpd might result in a Denial of Service condition. lighttpd 2010-06-03 2010-06-03 303213 remote 1.4.25-r1 1.4.25-r1

lighttpd is a lightweight high-performance web server.

Li Ming reported that lighttpd does not properly process packets that are sent overly slow.

A remote attacker might send specially crafted packets to a server running lighttpd, possibly resulting in a Denial of Service condition via host memory exhaustion.

There is no known workaround at this time.

All lighttpd users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/lighttpd-1.4.25-r1"
CVE-2010-0295 keytoaster a3li a3li