CVE-2012-5533
MEDIUM 5.0EPSS 12.0%
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 12.04% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2012-11-24
- Updated
- 2024-08-06