Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-30522

Опубликовано: 09 июн. 2022
Источник: debian
EPSS Средний

Описание

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.54-1package
apache2fixed2.4.54-1~deb11u1bullseyepackage
apache2fixed2.4.38-3+deb10u8busterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2022/06/08/6

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2022-30522

  • https://github.com/apache/httpd/commit/db47781128e42bd49f55076665b3f6ca4e2bc5e2

  • https://github.com/apache/httpd/commit/96c75bba15b6ce20eb8d34aad717a046c000b233

EPSS

Процентиль: 94%
0.15076
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

CVSS3: 7.5
redhat
около 3 лет назад

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

CVSS3: 7.5
nvd
около 3 лет назад

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

CVSS3: 7.5
github
около 3 лет назад

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

CVSS3: 6.8
fstec
около 3 лет назад

Уязвимость фильтра содержимого mod_sed веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 94%
0.15076
Средний
Уязвимость CVE-2022-30522