Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:7711

Опубликовано: 10 мая 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: apr security update

The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and other projects. It provides a free library of C data structures and routines.

Security Fix(es):

  • apr: integer overflow/wraparound in apr_encode (CVE-2022-24963)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
apr-develi68612.el9_3apr-devel-1.7.0-12.el9_3.i686.rpm
apr-develx86_6412.el9_3apr-devel-1.7.0-12.el9_3.x86_64.rpm
apri68612.el9_3apr-1.7.0-12.el9_3.i686.rpm
aprx86_6412.el9_3apr-1.7.0-12.el9_3.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 3 лет назад

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

CVSS3: 6.5
redhat
около 3 лет назад

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

CVSS3: 9.8
nvd
около 3 лет назад

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

CVSS3: 9.8
msrc
7 месяцев назад

Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions

CVSS3: 9.8
debian
около 3 лет назад

Integer Overflow or Wraparound vulnerability in apr_encode functions o ...