Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE: 2022:0024-1 Important: Lighttpd Off-By-One Overflow DoS

opensuse
Calendar Grey February 2, 2022
Dist Opensuse Esm H88
The recent patch addresses a critical vulnerability in lighttpd for openSUSE, reinforcing overall system safety and maintaining service reliability.
An update that solves one vulnerability and has two fixes is now available

Description

This update for lighttpd fixes the following issues:

lighttpd was updated to 1.4.64:

* CVE-2022-22707: off-by-one stack overflow in the mod_extforward plugin

(boo#1194376)

* graceful restart/shutdown timeout changed from 0 (disabled) to 8

seconds. configure an alternative with: server.feature-flags + (???server.graceful-shutdown-timeout??? => 8)

* deprecated modules (previously announced) have been removed:

mod_authn_mysql, mod_mysql_vhost, mod_cml, mod_flv_streaming, mod_geoip,

mod_trigger_b4_dl

update to 1.4.63:

* import xxHash v0.8.1

* fix reqpool mem corruption in 1.4.62

includes changes in 1.4.62:

* [mod_alias] fix use-after-free bug

* many developer visible bug fixes

update to 1.4.61:

* mod_dirlisting: sort "../" to top

* fix HTTP/2 upload > 64k w/ max-request-size

* code level and developer visible bug fixes

update to 1.4.60:

* HTTP/2 smoother and lower memory use (in general)

* HTTP/2...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP3:

zypper in -t patch openSUSE-2022-24=1

Package List

- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64):

lighttpd-1.4.64-bp153.2.3.1

lighttpd-mod_authn_gssapi-1.4.64-bp153.2.3.1

lighttpd-mod_authn_ldap-1.4.64-bp153.2.3.1

lighttpd-mod_authn_pam-1.4.64-bp153.2.3.1

lighttpd-mod_authn_sasl-1.4.64-bp153.2.3.1

lighttpd-mod_magnet-1.4.64-bp153.2.3.1

lighttpd-mod_maxminddb-1.4.64-bp153.2.3.1

lighttpd-mod_rrdtool-1.4.64-bp153.2.3.1

lighttpd-mod_vhostdb_dbi-1.4.64-bp153.2.3.1

lighttpd-mod_vhostdb_ldap-1.4.64-bp153.2.3.1

lighttpd-mod_vhostdb_mysql-1.4.64-bp153.2.3.1

lighttpd-mod_vhostdb_pgsql-1.4.64-bp153.2.3.1

lighttpd-mod_webdav-1.4.64-bp153.2.3.1

References

https://www.suse.com/security/cve/CVE-2022-22707.html

https://bugzilla.suse.com/1146452

https://bugzilla.suse.com/1181400

https://bugzilla.suse.com/1194376

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:0024-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here