Fiche vulnérabilité
CVE-2022-37797 : faille élevée lighttpd lighttpd (CVSS 7.5)
Description
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 12 sept. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- lighttpd lighttpd
- debian debian linux