Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cm5p-p299-9f4g

Опубликовано: 13 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

EPSS

Процентиль: 49%
0.00257
Низкий

7.5 High

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

CVSS3: 7.5
nvd
почти 3 года назад

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

CVSS3: 7.5
debian
почти 3 года назад

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler functio ...

suse-cvrf
больше 2 лет назад

Security update for lighttpd

redos
больше 2 лет назад

Уязвимость lighttpd

EPSS

Процентиль: 49%
0.00257
Низкий

7.5 High

CVSS3

Дефекты

CWE-476