Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-41556
HistoryOct 06, 2022 - 12:00 a.m.

CVE-2022-41556

2022-10-0600:00:00
ubuntu.com
ubuntu.com
20
resource leak
lighttpd
denial of service
tcp behavior
rdhup handling

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

62.2%

A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could
lead to a denial of service (connection-slot exhaustion) after a large
amount of anomalous TCP behavior by clients. It is related to RDHUP
mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is,
for example, affected. This is fixed in 1.4.67.

OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchlighttpd< 1.4.63-1ubuntu3.1UNKNOWN
ubuntu22.10noarchlighttpd< 1.4.65-2ubuntu1.1UNKNOWN
ubuntu14.04noarchlighttpd< anyUNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

62.2%