Lucene search

K
redosRedosROS-20221004-02
HistoryOct 04, 2022 - 12:00 a.m.

ROS-20221004-02

2022-10-0400:00:00
redos.red-soft.ru
6
vulnerability
lighttpd
mod_wstunnel
http requests
denial of service
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.7%

Vulnerability of lighttpd web server is related to a null pointer dereferencing error in mod_wstunnel module
module when processing invalid HTTP requests. Exploitation of the vulnerability could allow an attacker,
remotely, send specially crafted HTTP requests to a vulnerable web server and execute a denial of service attack.
A denial of service (DoS) attack

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64lighttpd< 1.4.64-2UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.7%