USN-5903-1: lighttpd vulnerabilities
28 February 2023
Several security issues were fixed in lighttpd.
Releases
Packages
- lighttpd - fast webserver with minimal memory footprint
Details
It was discovered that lighttpd incorrectly handled certain inputs, which could
result in a stack buffer overflow. A remote attacker could possibly use this
issue to cause a denial of service (DoS). (CVE-2022-22707, CVE-2022-41556)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
Ubuntu 22.04
Ubuntu 20.04
After a standard system update you need to restart lighttpd to make
all the necessary changes.