QID 150534
Date Published: 2022-06-24
QID 150534: Lighttpd server Denial of service (DoS) Vulnerability (CVE-2022-30780)
Lighttpd is a secure, fast, compliant, and very flexible web-server that has been optimized for high-performance environment.
Affected versions of lighttpd server suffer from a Denial of service (DoS) vulnerability which increases CPU consumption from stuck connections. The vulnerability occurs due to connection_read_header_more in connections.c file which has a typo that disrupts use of multiple read operations on large headers.
Affected versions:
lighttpd version from 1.4.56 to 1.4.58
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks the HTTP response headers to confirm if the host is running vulnerable version of lighttpd server.
Successful exploitation of the vulnerability could allows a remote attacker to cause a Denial of service (DoS) attack.
- Lighttpd -
redmine.lighttpd.net/issues/3059
CVEs related to QID 150534
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Lighttpd downloads |
|