Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-28330

Опубликовано: 08 июн. 2022
Источник: redhat
CVSS3: 5.3

Описание

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

An out-of-bounds read vulnerability was found in the mod_isapi module of httpd. The issue occurs when httpd is configured to process requests with the mod_isapi module.

Отчет

Httpd, as shipped with Red Hat Enterprise Linux 6, 7, 8, 9, and RHSCL, is not affected by this flaw because it does not ship the mod_isapi module. The mod_isapi module is shipped by Windows systems only.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
Red Hat Enterprise Linux 8httpd:2.4/httpdNot affected
Red Hat Enterprise Linux 9httpdNot affected
Red Hat JBoss Enterprise Application Platform 6httpd22Not affected
Red Hat JBoss Web Server 3httpd24Not affected
Red Hat Software Collectionshttpd24-httpdNot affected
Text-Only JBCSjbcs-httpd24-httpdFixedRHSA-2022:884108.12.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2095000httpd: mod_isapi: out-of-bounds read

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

CVSS3: 5.3
nvd
около 3 лет назад

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

CVSS3: 5.3
debian
около 3 лет назад

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bound ...

CVSS3: 5.3
github
около 3 лет назад

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость модуля mod_isapi веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании

5.3 Medium

CVSS3