[DW-VA1P4xT] Security scan vulnerability found
Description
VA1P4xT (VMAX A1 G3 FW: 1.0.1.64)
Customer is reporting -
A security scan says our DW-VA1P4xT is vulnerable to the below issue:
https://www.cvedetails.com/cve/CVE-2022-41556
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
I have 1.0.1.64 installed. Will there be an update to correct this problem?
This looks very similar (based on the description) to the problem we encountered a few months back. Did you have a chance to investigate this? The above issue may resolve it.
Please let me know what will be done.
Attachments
Upload attachments
Drop your files to upload
(Max file size: 1.00 GiB)