CVE-2007-1870

Publication date 18 April 2007

Last updated 24 July 2024


Ubuntu priority

lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointer dereference.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
lighttpd 7.04 feisty
Fixed 1.4.13-9ubuntu4.2
6.10 edgy
Fixed 1.4.13~r1370-1ubuntu1.3
6.06 LTS dapper
Fixed 1.4.11-3ubuntu3.5