In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded header in a somewhat unusual manner. Also, a 32-bit system is much more likely to be affected than a 64-bit system.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade lighttpd | Mar 26, 2024 | Jan 6, 2022 |
| Debian | — | Upgrade lighttpd | Jan 13, 2022 | Jan 6, 2022 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Mar 10, 2022 | Jan 6, 2022 |
| Suse | — | Upgrade lighttpd-mod_webdavUpgrade lighttpd-mod_vhostdb_pgsqlUpgrade lighttpd-mod_authn_pamUpgrade lighttpdUpgrade lighttpd-mod_authn_gssapiUpgrade lighttpd-mod_vhostdb_mysqlUpgrade lighttpd-mod_vhostdb_dbiUpgrade lighttpd-mod_magnetUpgrade lighttpd-mod_authn_saslUpgrade lighttpd-mod_maxminddbUpgrade lighttpd-mod_authn_ldapUpgrade lighttpd-mod_rrdtoolUpgrade lighttpd-mod_vhostdb_ldap | Feb 3, 2022 | Jan 6, 2022 |
| Ubuntu | — | Upgrade lighttpd | Mar 22, 2023 | Jan 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub