[ GLSA 202210-12 ] Lighttpd: Denial of Service

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <166717855903.9.4850526618384822655@90bb6a0775af>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202210-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Low
    Title: Lighttpd: Denial of Service
     Date: October 31, 2022
     Bugs: #869890
       ID: 202210-12

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability has been discovered in lighttpd which could result in
denial of service.

Background
==========

Lighttpd is a lightweight high-performance web server.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  www-servers/lighttpd       < 1.4.67                    >= 1.4.67

Description
===========

Lighttpd's mod_wstunnel does not initialize a handler function pointer
if an invalid HTTP request (websocket handshake) is received.

Impact
======

An attacker can trigger a denial of service via making Lighttpd try to
call an uninitialized function pointer.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All lighttpd users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=www-servers/lighttpd-1.4.67"

References
==========

[ 1 ] CVE-2022-37797
      https://nvd.nist.gov/vuln/detail/CVE-2022-37797
[ 2 ] CVE-2022-41556
      https://nvd.nist.gov/vuln/detail/CVE-2022-41556

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202210-12

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmNfID4ACgkQFMQkOaVy
+9lhfw/5AeNVWda5i1k5lxj/vT46XMbXFj1r4lVyTGNb2NwFbFzqxk8j+J9o/Oss
kpZK5v4LiWFn53DIVE7CiGwZSHdttfBnmszmKm3P4UUi9/U+14hcoFTEdPq2H7By
FP6BZQJVEAnXhfoN7ohUw8qJQeeWb3UNTaHExl4ofvVm25wT/1QD3Bc2MtoUhnax
uKiPJ45ppt9pmVmlwtY3Paxq1Px1esvcK+zlVvjiYpghrDd7o0o8Ge+FhywT/ylY
1bXqkR70xygOzsApjOgR0qipPD/jvvl2e6ca79H+ITGKln4DwxTPCFclcqsKUGRl
5eo3RGqnzD/NY7GP5/ksiRXBeVt4PH3iDJUXduamLP+fc+zoQotix/JA2sIG7CnC
/bFXrMzR/c8Zba48cYhZ2qmQRvwFkeBdc4QO3U8lZed2LNwx2Bc2CJ1M3h7R8AgP
vta3BPpSC5f7p4fg/ttwF6G+u80xS3J40ZOfis6N8Zz0ZVLgTYpRUyyVrKipXlNr
tsKzq9vQSHS+0BtCoYQltNZyhmX+glmCb97/8maa0IBCKSkN09RSh21N+GoB1iUH
770jfuwC1xLhJ9yDKdDTD1wB0kkEodi4ZkPCtc/H092f0HrGhx1R0R+14WxCoXEc
cx8d4Jx7jaoRrpt9eOhCLruN01aXdDiXJGrq3orgdk81AvNHPBM=
=UdYz
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.