Upstream information
Description
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Novell/SUSE information
Novell Bugzilla entry: 790258 SUSE Security Advisories:- openSUSE-SU-2012:1532-1, published Fri, 23 Nov 2012 13:08:24 +0100 (CET)
