Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24963

Опубликовано: 31 янв. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

A flaw was found in Apache Portable Runtime (APR). This issue may allow a malicious attacker to write beyond the bounds of a buffer.

Отчет

Versions of "apr-util" shipped with Red Hat Enterprise Linux-6, 7, 8, and 9 are not affected. "apr_encode_*" API, which contains the affected code was added in apr-utils v1.7.0, whereas, RHEL ships apr-util v1.6.1 and lower.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6aprNot affected
Red Hat Enterprise Linux 6apr-utilNot affected
Red Hat Enterprise Linux 7aprNot affected
Red Hat Enterprise Linux 7apr-utilNot affected
Red Hat Enterprise Linux 8aprNot affected
Red Hat Enterprise Linux 8apr-utilNot affected
Red Hat Enterprise Linux 9apr-utilNot affected
JBoss Core Services for RHEL 8jbcs-httpd24-aprFixedRHSA-2023:462915.08.2023
JBoss Core Services on RHEL 7jbcs-httpd24-aprFixedRHSA-2023:462915.08.2023
JWS 5.7.4 releaseaprFixedRHSA-2023:491004.09.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2169465apr: integer overflow/wraparound in apr_encode

EPSS

Процентиль: 33%
0.00129
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

CVSS3: 9.8
nvd
больше 2 лет назад

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

CVSS3: 9.8
debian
больше 2 лет назад

Integer Overflow or Wraparound vulnerability in apr_encode functions o ...

CVSS3: 9.8
github
больше 2 лет назад

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

oracle-oval
больше 1 года назад

ELSA-2023-7711: apr security update (MODERATE)

EPSS

Процентиль: 33%
0.00129
Низкий

6.5 Medium

CVSS3