{"id":"openSUSE-SU-2022:10132-1","summary":"Security update for lighttpd","details":"This update for lighttpd fixes the following issues:\n\nlighttpd was updated to 1.4.66:\n\n* a number of bug fixes\n* Fix HTTP/2 downloads \u003e= 4GiB\n* Fix SIGUSR1 graceful restart with TLS\n* futher bug fixes\n* CVE-2022-37797: null pointer dereference in mod_wstunnel,\n  possibly a remotely triggerable crash (boo#1203358)\n* In an upcoming release the TLS modules will default to using\n  stronger, modern chiphers and will default to allow client\n  preference in selecting ciphers.\n  “CipherString” =\u003e “EECDH+AESGCM:AES256+EECDH:CHACHA20:SHA256:!SHA384”,\n  “Options” =\u003e “-ServerPreference”\n  old defaults:\n  “CipherString” =\u003e “HIGH”,\n  “Options” =\u003e “ServerPreference”\n* A number of TLS options are how deprecated and will be removed\n  in a future release:\n  – ssl.honor-cipher-order\n  – ssl.dh-file\n  – ssl.ec-curve\n  – ssl.disable-client-renegotiation\n  – ssl.use-sslv2\n  – ssl.use-sslv3\n  The replacement option is ssl.openssl.ssl-conf-cmd, but lighttpd\n  defaults should be prefered\n* A number of modules are now deprecated and will be removed in a\n  future release: mod_evasive, mod_secdownload, mod_uploadprogress,\n  mod_usertrack can be replaced by mod_magnet and a few lines of lua.\n\nupdate to 1.4.65:\n\n* WebSockets over HTTP/2\n* RFC 8441 Bootstrapping WebSockets with HTTP/2\n* HTTP/2 PRIORITY_UPDATE\n* RFC 9218 Extensible Prioritization Scheme for HTTP\n* prefix/suffix conditions in lighttpd.conf\n* mod_webdav safe partial-PUT\n* webdav.opts += (“partial-put-copy-modify” =\u003e “enable”)\n* mod_accesslog option: accesslog.escaping = “json”\n* mod_deflate libdeflate build option\n* speed up request body uploads via HTTP/2\n* Behavior Changes\n* change default server.max-keep-alive-requests = 1000 to adjust\n* to increasing HTTP/2 usage and to web2/web3 application usage\n* (prior default was 100)\n* mod_status HTML now includes HTTP/2 control stream id 0 in the output\n* which contains aggregate counts for the HTTP/2 connection\n* (These lines can be identified with URL ‘*’, part of “PRI *” preface)\n* alternative: https://wiki.lighttpd.net/ModMagnetExamples#lua-mod_status\n* MIME type application/javascript is translated to text/javascript (RFC 9239)\n","modified":"2026-03-11T07:33:34.761368Z","published":"2022-09-29T09:54:26Z","related":["CVE-2022-37797"],"upstream":["CVE-2022-37797"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATUOJQDWIRALBMVI5GOSOGPZP5AWVAZF/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203358"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-37797"}],"affected":[{"package":{"name":"lighttpd","ecosystem":"SUSE:Package Hub 15 SP3","purl":"pkg:rpm/suse/lighttpd&distro=SUSE%20Package%20Hub%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.66-bp154.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"lighttpd-mod_webdav":"1.4.66-bp154.2.3.1","lighttpd":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_gssapi":"1.4.66-bp154.2.3.1","lighttpd-mod_magnet":"1.4.66-bp154.2.3.1","lighttpd-mod_maxminddb":"1.4.66-bp154.2.3.1","lighttpd-mod_rrdtool":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_mysql":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_pgsql":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_ldap":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_pam":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_sasl":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_dbi":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_ldap":"1.4.66-bp154.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10132-1.json"}},{"package":{"name":"lighttpd","ecosystem":"SUSE:Package Hub 15 SP4","purl":"pkg:rpm/suse/lighttpd&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.66-bp154.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"lighttpd-mod_authn_pam":"1.4.66-bp154.2.3.1","lighttpd-mod_magnet":"1.4.66-bp154.2.3.1","lighttpd-mod_rrdtool":"1.4.66-bp154.2.3.1","lighttpd":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_gssapi":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_sasl":"1.4.66-bp154.2.3.1","lighttpd-mod_maxminddb":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_dbi":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_ldap":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_mysql":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_pgsql":"1.4.66-bp154.2.3.1","lighttpd-mod_webdav":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_ldap":"1.4.66-bp154.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10132-1.json"}},{"package":{"name":"lighttpd","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/lighttpd&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.66-bp154.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"lighttpd-mod_vhostdb_mysql":"1.4.66-bp154.2.3.1","lighttpd-mod_webdav":"1.4.66-bp154.2.3.1","lighttpd":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_ldap":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_pam":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_sasl":"1.4.66-bp154.2.3.1","lighttpd-mod_magnet":"1.4.66-bp154.2.3.1","lighttpd-mod_rrdtool":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_dbi":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_ldap":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_pgsql":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_gssapi":"1.4.66-bp154.2.3.1","lighttpd-mod_maxminddb":"1.4.66-bp154.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10132-1.json"}},{"package":{"name":"lighttpd","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/lighttpd&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.66-bp154.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"lighttpd-mod_vhostdb_dbi":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_mysql":"1.4.66-bp154.2.3.1","lighttpd-mod_webdav":"1.4.66-bp154.2.3.1","lighttpd":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_sasl":"1.4.66-bp154.2.3.1","lighttpd-mod_magnet":"1.4.66-bp154.2.3.1","lighttpd-mod_maxminddb":"1.4.66-bp154.2.3.1","lighttpd-mod_rrdtool":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_ldap":"1.4.66-bp154.2.3.1","lighttpd-mod_vhostdb_pgsql":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_gssapi":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_ldap":"1.4.66-bp154.2.3.1","lighttpd-mod_authn_pam":"1.4.66-bp154.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10132-1.json"}}],"schema_version":"1.7.5"}