Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-70073
HistoryJan 08, 2022 - 12:00 a.m.

lighttpd buffer overflow vulnerability

2022-01-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
56
lighttpd
buffer overflow
web server
vulnerability
mod_extforward plugin
memory boundaries
exploit

EPSS

0.031

Percentile

91.2%

lighttpd is an open source web server. buffer overflow vulnerability exists in versions 1.4.46 to 1.4.63 of lighttpd, which stems from the failure of the mod_extforward_Forwarded function in the product’s mod_extforward plugin to effectively handle memory boundaries. An attacker could exploit this vulnerability to cause a buffer overflow.