CVE-2022-37797

Source
https://cve.org/CVERecord?id=CVE-2022-37797
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37797.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-37797
Downstream
Related
Published
2022-09-12T00:00:00Z
Modified
2026-08-12T03:51:47.444639192Z
Summary
[none]
Details

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37797.json"
}
References

Affected packages

Git / github.com/lighttpd/lighttpd1.4

Affected ranges

Type
GIT
Repo
https://github.com/lighttpd/lighttpd1.4
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.4.65"
        },
        {
            "last_affected": "1.4.65"
        }
    ],
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:lighttpd:lighttpd:1.4.65:*:*:*:*:*:*:*"
}

Affected versions

1.*
1.4.65
lighttpd-1.*
lighttpd-1.4.65

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37797.json"