CVE-2022-37797
published 2022-09-12CVE-2022-37797: In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.03%
78.8th percentile
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | lighttpd | < lighttpd 1.4.66-1 (bookworm) | lighttpd 1.4.66-1 (bookworm) |
| lighttpd | lighttpd | — | — |
| lighttpd | lighttpd | >= 0 < 1.4.59-1+deb11u2 | 1.4.59-1+deb11u2 |
| lighttpd | lighttpd | >= 0 < 1.4.66-1 | 1.4.66-1 |
| lighttpd | lighttpd | >= 0 < 1.4.66-1 | 1.4.66-1 |
| lighttpd | lighttpd | >= 0 < 1.4.66-1 | 1.4.66-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cm5p-p299-9f4g: In lighttpd 1
ghsa_unreviewed·2022-09-13
CVE-2022-37797 [HIGH] CWE-476 GHSA-cm5p-p299-9f4g: In lighttpd 1
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
OSV
CVE-2022-37797: In lighttpd 1
osv·2022-09-12·CVSS 7.5
CVE-2022-37797 [HIGH] CVE-2022-37797: In lighttpd 1
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Debian
CVE-2022-37797: lighttpd - In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer ...
vendor_debian·2022·CVSS 7.5
CVE-2022-37797 [HIGH] CVE-2022-37797: lighttpd - In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer ...
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
Scope: local
bookworm: resolved (fixed in 1.4.66-1)
bullseye: resolved (fixed in 1.4.59-1+deb11u2)
forky: resolved (fixed in 1.4.66-1)
sid: resolved (fixed in 1.4.66-1)
trixie: resolved (fixed in 1.4.66-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/10/msg00002.htmlhttps://redmine.lighttpd.net/issues/3165https://security.gentoo.org/glsa/202210-12https://www.debian.org/security/2022/dsa-5243https://lists.debian.org/debian-lts-announce/2022/10/msg00002.htmlhttps://redmine.lighttpd.net/issues/3165https://security.gentoo.org/glsa/202210-12https://www.debian.org/security/2022/dsa-5243
2022-09-12
Published