Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-37797

Опубликовано: 12 сент. 2022
Источник: debian
EPSS Низкий

Описание

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lighttpdfixed1.4.66-1package

Примечания

  • https://redmine.lighttpd.net/issues/3165

  • https://git.lighttpd.net/lighttpd/lighttpd1.4/commit/971773f1fae600074b46ef64f3ca1f76c227985f (lighttpd-1.4.66)

EPSS

Процентиль: 56%
0.00335
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

CVSS3: 7.5
nvd
около 3 лет назад

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

suse-cvrf
около 3 лет назад

Security update for lighttpd

redos
около 3 лет назад

Уязвимость lighttpd

CVSS3: 7.5
github
около 3 лет назад

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

EPSS

Процентиль: 56%
0.00335
Низкий