PT-2022-4993 · Lighttpd+4 · Mod Fastcgi+5

Published

2022-09-02

·

Updated

2024-06-15

·

CVE-2022-41556

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions lighttpd versions 1.4.56 through 1.4.66
Description A resource leak in gw backend.c could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. The use of mod fastcgi is affected.
Recommendations For versions 1.4.56 through 1.4.66, update to version 1.4.67 to resolve the issue. As a temporary workaround, consider restricting the use of mod fastcgi until a patch is available.

Exploit

Fix

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2649
ALT-PU-2022-2735
ALT-PU-2022-2863
BDU:2022-06197
CVE-2022-41556
DSA-5243-1
MGASA-2022-0369
OESA-2022-1989
OPENSUSE-SU-2022:10140-1
OPENSUSE-SU-2024:12382-1
USN-5903-1

Affected Products

Alt Linux
Lighttpd
Linuxmint
Red Os
Ubuntu
Mod Fastcgi