[DW-VA1P4xT] Security scan vulnerability found

Description

VA1P4xT (VMAX A1 G3 FW: 1.0.1.64)


 Customer is reporting -

A security scan says our DW-VA1P4xT is vulnerable to the below issue:

https://www.cvedetails.com/cve/CVE-2022-41556
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.

I have 1.0.1.64 installed.  Will there be an update to correct this problem?

This looks very similar (based on the description) to the problem we encountered a few months back.  Did you have a chance to investigate this?  The above issue may resolve it.

Please let me know what will be done.

Attachments

Upload attachments

Drop your files to upload

(Max file size: 1.00 GiB)

Uploading...
(Template) Current File Name (1 / 7) 123KB / 2.1MB
(Template) File Name 123KB / 2.1MB
Upload completed. Click here to reload the page.

Child issues

Linked work items

Activity