QID 87543
QID 87543: Lighttpd server Denial of service (DoS) Vulnerability (CVE-2022-22707)
lighttpd is an open-source web server optimized for speed-critical environments while remaining standards-compliant, secure, and flexible.
mod_auth in lighttpd allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.
Affected Version:
lighttpd versions before 1.4.46 to 1.4.63
QID Detection Logic (Unauthenticated):
It uses banner check the vulnerable version of lighttpd
Successful exploitation of the vulnerability could allows a remote attacker to cause a Denial of service (DoS) attack.
Solution
Customers are advised to upgrade lighttpd server to latest version to remediate the vulnerability.
Vendor References
- Lighttpd -
redmine.lighttpd.net/issues/3134
CVEs related to QID 87543
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| lighttpd |
|