Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-22721

Опубликовано: 14 мар. 2022
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 5.8
CVSS3: 9.1

Описание

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

РелизСтатусПримечание
bionic

released

2.4.29-1ubuntu4.22
devel

released

2.4.52-1ubuntu2
esm-infra-legacy/trusty

not-affected

2.4.7-1ubuntu4.22+esm4
esm-infra/bionic

not-affected

2.4.29-1ubuntu4.22
esm-infra/focal

not-affected

2.4.41-4ubuntu3.10
esm-infra/xenial

released

2.4.18-2ubuntu3.17+esm5
focal

released

2.4.41-4ubuntu3.10
impish

released

2.4.48-3.1ubuntu3.3
jammy

released

2.4.52-1ubuntu2
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 96%
0.23333
Средний

5.8 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
больше 3 лет назад

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.1
nvd
больше 3 лет назад

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.1
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 9.1
debian
больше 3 лет назад

If LimitXMLRequestBody is set to allow request bodies larger than 350M ...

CVSS3: 9.8
github
больше 3 лет назад

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

EPSS

Процентиль: 96%
0.23333
Средний

5.8 Medium

CVSS2

9.1 Critical

CVSS3