4.3
CVSSv2

CVE-2022-22707

Published: 06/01/2022 Updated: 13/01/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In lighttpd 1.4.46 up to and including 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded header in a somewhat unusual manner. Also, a 32-bit system is much more likely to be affected than a 64-bit system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lighttpd lighttpd

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

An out-of-bounds memory access was discovered in the mod_extforward plugin of the lighttpd web server, which may result in denial of service For the oldstable distribution (buster), this problem has been fixed in version 1453-4+deb10u2 For the stable distribution (bullseye), this problem has been fixed in version 1459-1+deb11u1 We recommend ...

Github Repositories

Config files for my GitHub profile.

👋 Hi, I’m @xmostunwantedx 👀 I’m interested in exploit cve 2022-22707 and 2010-0295 🌱 I’m currently learning but still haven't figured out Linux 💞️ point is I'm slow, but I have been watching just don't understand why I can't get Linux to run on my laptops It crashes on eee PC 900 and HP dv4 win vista No ma

Get (security) info about IP addresses

checkip Sometimes I come across an IP address, for example when reviewing logs And I'd like to find out more about this numerical label Checkip is CLI tool and Go library that provides generic and security information about IP addresses in a quick way $ checkip 9122816647 --- 9122816647 --- db-ipcom Petržalka, Slovakia dns name skh1-webredir01-vese