Memory leak in lighttpd - CVE-2022-41556
Published: September 29, 2022
Vulnerability identifier: #VU67733
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41556
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak within the mod_fastcgi and mod_scgi modules when handling a large number of incorrect HTTP requests. A remote attacker can send multiple incorrect HTTP requests to the web server and perform denial of service attack.
Affected software
lighttpd
Debian Linux
Gentoo Linux
Fedora
Oracle Solaris
openEuler
Ubuntu
lighttpd (Ubuntu package)
lighttpd (Debian package)
www-servers/lighttpd
lighttpd
lighttpd-fastcgi
lighttpd-mod_mysql_vhost
lighttpd-debuginfo
lighttpd-mod_authn_gssapi
lighttpd-debugsource
lighttpd-mod_authn_pam
lighttpd-mod_authn_mysql
lighttpd-filesystem
Debian Linux
Gentoo Linux
Fedora
Oracle Solaris
openEuler
Ubuntu
lighttpd (Ubuntu package)
lighttpd (Debian package)
www-servers/lighttpd
lighttpd
lighttpd-fastcgi
lighttpd-mod_mysql_vhost
lighttpd-debuginfo
lighttpd-mod_authn_gssapi
lighttpd-debugsource
lighttpd-mod_authn_pam
lighttpd-mod_authn_mysql
lighttpd-filesystem
How to mitigate CVE-2022-41556
Install updates from vendor's website.
lighttpd - update to 1.4.67
lighttpd (Ubuntu package) - addressed in versions 1.4.55-1ubuntu1.20.04.2, 1.4.63-1ubuntu3.1, 1.4.65-2ubuntu1.1
lighttpd (Debian package) - update to 1.4.59-1+deb11u2
www-servers/lighttpd - update to 1.4.67
lighttpd - update to 1.4.67-1
lighttpd-fastcgi - update to 1.4.67-1
lighttpd-mod_mysql_vhost - update to 1.4.67-1
lighttpd-debuginfo - update to 1.4.67-1
lighttpd-mod_authn_gssapi - update to 1.4.67-1
lighttpd-debugsource - update to 1.4.67-1
lighttpd-mod_authn_pam - update to 1.4.67-1
lighttpd-mod_authn_mysql - update to 1.4.67-1
lighttpd-filesystem - update to 1.4.67-1
lighttpd - addressed in versions 1.4.67-1.el8, 1.4.67-1.fc35
lighttpd (Ubuntu package) - addressed in versions 1.4.55-1ubuntu1.20.04.2, 1.4.63-1ubuntu3.1, 1.4.65-2ubuntu1.1
lighttpd (Debian package) - update to 1.4.59-1+deb11u2
www-servers/lighttpd - update to 1.4.67
lighttpd - update to 1.4.67-1
lighttpd-fastcgi - update to 1.4.67-1
lighttpd-mod_mysql_vhost - update to 1.4.67-1
lighttpd-debuginfo - update to 1.4.67-1
lighttpd-mod_authn_gssapi - update to 1.4.67-1
lighttpd-debugsource - update to 1.4.67-1
lighttpd-mod_authn_pam - update to 1.4.67-1
lighttpd-mod_authn_mysql - update to 1.4.67-1
lighttpd-filesystem - update to 1.4.67-1
lighttpd - addressed in versions 1.4.67-1.el8, 1.4.67-1.fc35