CVE-2012-5533

lighttpd < 1.4.32 - Denial of Service via Empty Token in Connection Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5533. PoCs published by t4c.

AI-analyzed exploit summary This exploit sends a malformed HTTP request with an invalid 'Connection' header to trigger a denial-of-service (DoS) condition in lighttpd 1.4.31. The vulnerability arises from improper handling of the 'Connection' header, causing the server to crash.

Description

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.

Exploits (1)

exploitdb WORKING POC
by t4c · bashdoslinux
https://www.exploit-db.com/exploits/22902

This exploit sends a malformed HTTP request with an invalid 'Connection' header to trigger a denial-of-service (DoS) condition in lighttpd 1.4.31. The vulnerability arises from improper handling of the 'Connection' header, causing the server to crash.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: lighttpd 1.4.31
No auth needed
Prerequisites: Network access to the target lighttpd server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (16)

Core 16
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/11/21/1
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-11/msg00044.html
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/22902
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027802
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51268
Third Party Advisory x_refsource_confirm
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0345
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/87623
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141576815022399&w=2
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2013:100
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/80213
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51298
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-01/msg00051.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56619

Scores

EPSS 0.1204
EPSS Percentile 95.6%

Details

CWE
CWE-399
Status published
Products (2)
lighttpd/lighttpd 1.4.31
lighttpd/lighttpd 1.4.32
Published Nov 24, 2012
Tracked Since Feb 18, 2026