CVE-2022-41556
published 2022-10-06CVE-2022-41556: A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.79%
84.8th percentile
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lighttpd | < lighttpd 1.4.67-1 (bookworm) | lighttpd 1.4.67-1 (bookworm) |
| fedoraproject | fedora | — | — |
| lighttpd | lighttpd | >= 0 < 1.4.59-1+deb11u2 | 1.4.59-1+deb11u2 |
| lighttpd | lighttpd | >= 0 < 1.4.67-1 | 1.4.67-1 |
| lighttpd | lighttpd | >= 0 < 1.4.67-1 | 1.4.67-1 |
| lighttpd | lighttpd | >= 0 < 1.4.67-1 | 1.4.67-1 |
| lighttpd | lighttpd | >= 0 < 1.4.55-1ubuntu1.20.04.2 | 1.4.55-1ubuntu1.20.04.2 |
| lighttpd | lighttpd | >= 0 < 1.4.63-1ubuntu3.1 | 1.4.63-1ubuntu3.1 |
| lighttpd | lighttpd | >= 1.4.56 < 1.4.67 | 1.4.67 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
lighttpd vulnerabilities
vendor_ubuntu·2023-02-28·CVSS 5.9
CVE-2022-41556 [MEDIUM] lighttpd vulnerabilities
Title: lighttpd vulnerabilities
Summary: Several security issues were fixed in lighttpd.
It was discovered that lighttpd incorrectly handled certain inputs, which could
result in a stack buffer overflow. A remote attacker could possibly use this
issue to cause a denial of service (DoS). (CVE-2022-22707, CVE-2022-41556)
Instructions: After a standard system update you need to restart lighttpd to make
all the necessary changes.
Debian
CVE-2022-41556: lighttpd - A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to ...
vendor_debian·2022·CVSS 7.5
CVE-2022-41556 [HIGH] CVE-2022-41556: lighttpd - A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to ...
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
Scope: local
bookworm: resolved (fixed in 1.4.67-1)
bullseye: resolved (fixed in 1.4.59-1+deb11u2)
forky: resolved (fixed in 1.4.67-1)
sid: resolved (fixed in 1.4.67-1)
trixie: resolved (fixed in 1.4.67-1)
OSV
lighttpd vulnerabilities
osv·2023-02-28·CVSS 5.9
CVE-2022-22707 [MEDIUM] lighttpd vulnerabilities
lighttpd vulnerabilities
It was discovered that lighttpd incorrectly handled certain inputs, which could
result in a stack buffer overflow. A remote attacker could possibly use this
issue to cause a denial of service (DoS). (CVE-2022-22707, CVE-2022-41556)
OSV
CVE-2022-41556: A resource leak in gw_backend
osv·2022-10-06·CVSS 7.5
CVE-2022-41556 [HIGH] CVE-2022-41556: A resource leak in gw_backend
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
GHSA
GHSA-jm88-vr5q-23rj: A resource leak in gw_backend
ghsa_unreviewed·2022-10-06
CVE-2022-41556 [HIGH] CWE-401 GHSA-jm88-vr5q-23rj: A resource leak in gw_backend
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.lighttpd.net/lighttpd/lighttpd1.4/commit/b18de6f9264f914f7bf493abd3b6059343548e50https://github.com/lighttpd/lighttpd1.4/compare/lighttpd-1.4.66...lighttpd-1.4.67https://github.com/lighttpd/lighttpd1.4/pull/115https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVOSBSCMLGCHH2Z74H64ZWVDFJFQTBC2/https://security.gentoo.org/glsa/202210-12https://git.lighttpd.net/lighttpd/lighttpd1.4/commit/b18de6f9264f914f7bf493abd3b6059343548e50https://github.com/lighttpd/lighttpd1.4/compare/lighttpd-1.4.66...lighttpd-1.4.67https://github.com/lighttpd/lighttpd1.4/pull/115https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVOSBSCMLGCHH2Z74H64ZWVDFJFQTBC2/https://security.gentoo.org/glsa/202210-12
2022-10-06
Published