Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-31122

Опубликовано: 19 окт. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.

A flaw was found in the mod_macro module of httpd. When processing a very long macro, the null byte terminator will not be added, leading to an out-of-bounds read, resulting in a crash.

Отчет

This flaw only affects configurations with mod_macro loaded and when a very long macro is configured and used, specifically a macro longer than 8191 characters. If these conditions are not present, the server is not affected and no further mitigation is needed. For more information about the mitigation, see the mitigation section below. The httpd mod_macro module is enabled by default in Red Hat Enterprise Linux 8, 9, and in RHSCL. However, there are no macros used in the default httpd configuration.

Меры по смягчению последствий

Disabling mod_macro and restarting httpd or making sure the macros used are smaller than the required length to trigger this vulnerability will mitigate this flaw. Furthermore, it's unlikely that a very long macro with the length needed to trigger this issue is being used.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift PipelineshttpdAffected
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat Enterprise Linux 7httpdOut of support scope
Red Hat JBoss Enterprise Application Platform 6httpd22Out of support scope
Red Hat OpenShift Data Science (RHODS)httpdWill not fix
Red Hat OpenShift GitOpshttpdWill not fix
Red Hat OpenStack Platform 16.1httpdNot affected
Red Hat OpenStack Platform 16.2httpdNot affected
Red Hat OpenStack Platform 17.1httpdNot affected
Red Hat OpenStack Platform 18.0httpdNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2245332httpd: mod_macro: out-of-bounds read vulnerability

EPSS

Процентиль: 45%
0.00219
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.

CVSS3: 7.5
nvd
почти 2 года назад

Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.

CVSS3: 7.5
debian
почти 2 года назад

Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.Th ...

suse-cvrf
больше 1 года назад

Security update for apache2

suse-cvrf
больше 1 года назад

Security update for apache2

EPSS

Процентиль: 45%
0.00219
Низкий

7.5 High

CVSS3