Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 22.10: USN-5903-1 Critical Lighttpd DoS Issues Report

ubuntu
Calendar Grey February 28, 2023
Scroller Ubuntu
Several security patches for lighttpd have addressed vulnerabilities impacting Ubuntu versions 20.04, 22.04, and 22.10.
Several security issues were fixed in lighttpd.

Summary

Several security issues were fixed in lighttpd.

Software Description:

- lighttpd: fast webserver with minimal memory footprint

Details:

It was discovered that lighttpd incorrectly handled certain inputs, which could

result in a stack buffer overflow. A remote attacker could possibly use this

issue to cause a denial of service (DoS). (CVE-2022-22707, CVE-2022-41556)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
  lighttpd                        1.4.65-2ubuntu1.1

Ubuntu 22.04 LTS:
  lighttpd                        1.4.63-1ubuntu3.1

Ubuntu 20.04 LTS:
  lighttpd                        1.4.55-1ubuntu1.20.04.2

After a standard system update you need to restart lighttpd to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5903-1

CVE-2022-22707, CVE-2022-41556

Severity
critical
Lowest
Low
Medium
High
Critical

February 28, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.