CVE-2022-37797

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
lighttpdlighttpd
1.4.65
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lighttpd
bookworm
1.4.69-1
fixed
bullseye
1.4.59-1+deb11u2
fixed
bullseye (security)
1.4.59-1+deb11u2
fixed
sid
1.4.76-1
fixed
trixie
1.4.76-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lighttpd
bionic
not-affected
focal
needed
jammy
needed
kinetic
ignored
lunar
ignored
mantic
not-affected
noble
not-affected
trusty
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
lighttpd
Amazon Linux 1
0:1.4.53-1.37.amzn1
fixed
lighttpd-debuginfo
Amazon Linux 1
0:1.4.53-1.37.amzn1
fixed
lighttpd-fastcgi
Amazon Linux 1
0:1.4.53-1.37.amzn1
fixed
lighttpd-mod_authn_gssapi
Amazon Linux 1
0:1.4.53-1.37.amzn1
fixed
lighttpd-mod_authn_mysql
Amazon Linux 1
0:1.4.53-1.37.amzn1
fixed
lighttpd-mod_authn_pam
Amazon Linux 1
0:1.4.53-1.37.amzn1
fixed
lighttpd-mod_geoip
Amazon Linux 1
0:1.4.53-1.37.amzn1
fixed
lighttpd-mod_mysql_vhost
Amazon Linux 1
0:1.4.53-1.37.amzn1
fixed