VDB

DEBIAN-CVE-2022-37797

DEBIAN-CVE-2022-37797 PUBLISHED CVSS 7.5 HIGH

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
lighttpdlighttpd
Debian:13lighttpd0, 0, 0
Debian:14lighttpd0, 0, 0
Debian:12lighttpd0, 0, 0
Debian:11lighttpd0, 1.4.59-1, 1.4.59-1

Timeline

  • Sep 12, 2022 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›