#VU67731 NULL pointer dereference in lighttpd - CVE-2022-37797
Published: September 29, 2022
lighttpd
lighttpd
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the mod_wstunnel module when handling invalid HTTP requests. A remote attacker can send specially crafted HTTP requests to the affected web server and perform a denial of service (DoS) attack.