Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25147

Опубликовано: 31 янв. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.

A flaw was found in the Apache Portable Runtime Utility (APR-util) library. This issue may allow a malicious attacker to cause an out-of-bounds write due to an integer overflow when encoding/decoding a very long string using the base64 family of functions.

Отчет

The Apache Portable Runtime Utility (APR-util) library contains additional utility interfaces for APR (Apache Portable Runtime). This vulnerability is related to the incorrect usage of the base64 encoding/decoding family of functions through APR-util API. Usage of these functions with long enough string would cause integer overflow and will lead to out-of-bound write. This flaw was rated with an important severity for a moment as Red Hat received information that this vulnerability potentially can allow remote attackers to cause a denial of service to the application linked to the APR-util library. Deep analysis confirmed that there are no known conditions that could lead to DoS. Additionally the APR-util API should not be exposed to the untrusted uploads and usage.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6apr-utilOut of support scope
JBCS httpd 2.4.51.sp2jbcs-httpd24-apr-utilFixedRHSA-2023:335505.06.2023
JBoss Core Services for RHEL 8jbcs-httpd24-apr-utilFixedRHSA-2023:335405.06.2023
JBoss Core Services on RHEL 7jbcs-httpd24-apr-utilFixedRHSA-2023:335405.06.2023
Red Hat Enterprise Linux 7apr-utilFixedRHSA-2023:314516.05.2023
Red Hat Enterprise Linux 8apr-utilFixedRHSA-2023:310916.05.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionsapr-utilFixedRHSA-2023:317717.05.2023
Red Hat Enterprise Linux 8.2 Advanced Update Supportapr-utilFixedRHSA-2023:338031.05.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update Serviceapr-utilFixedRHSA-2023:338031.05.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionsapr-utilFixedRHSA-2023:338031.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2169652apr-util: out-of-bounds writes in the apr_base64

EPSS

Процентиль: 11%
0.0004
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.

CVSS3: 6.5
nvd
больше 2 лет назад

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.

CVSS3: 6.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 6.5
debian
больше 2 лет назад

Integer Overflow or Wraparound vulnerability in apr_base64 functions o ...

suse-cvrf
больше 2 лет назад

Security update for apr-util

EPSS

Процентиль: 11%
0.0004
Низкий

6.5 Medium

CVSS3