Описание
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 2.4.29-1ubuntu4.24 |
devel | released | 2.4.54-2ubuntu1 |
esm-infra-legacy/trusty | not-affected | 2.4.7-1ubuntu4.22+esm8 |
esm-infra/bionic | not-affected | 2.4.29-1ubuntu4.24 |
esm-infra/focal | not-affected | 2.4.41-4ubuntu3.12 |
esm-infra/xenial | released | 2.4.18-2ubuntu3.17+esm6 |
focal | released | 2.4.41-4ubuntu3.12 |
impish | released | 2.4.48-3.1ubuntu3.5 |
jammy | released | 2.4.52-1ubuntu4.1 |
kinetic | released | 2.4.54-2ubuntu1 |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
Apache HTTP Server 2.4.53 and earlier may return lengths to applicatio ...
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
Уязвимость функции r:wsread() модуля mod_lua веб-сервера Apache HTTP Server, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
5 Medium
CVSS2
7.5 High
CVSS3