CVE-2022-23943
Description
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
CWE
- CWE-787 — CWE-787 Out-of-bounds Write
- CWE-190 — CWE-190 Integer Overflow or Wraparound
Affected
- Apache Software Foundation / Apache HTTP Server — v=2.4 ≤2.4.52 [affected]
CVSS
- (none)
References
- https://httpd.apache.org/security/vulnerabilities_24.html x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2022/03/14/1 mailing-list, x_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/ vendor-advisory, x_refsource_FEDORA
- https://lists.debian.org/debian-lts-announce/2022/03/msg00033.html mailing-list, x_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/ vendor-advisory, x_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/ vendor-advisory, x_refsource_FEDORA
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISC
- https://www.tenable.com/security/tns-2022-08 x_refsource_CONFIRM
- https://security.netapp.com/advisory/ntap-20220321-0001/ x_refsource_CONFIRM
- https://www.tenable.com/security/tns-2022-09 x_refsource_CONFIRM
- https://security.gentoo.org/glsa/202208-20 vendor-advisory, x_refsource_GENTOO
Source
cvelistV5-main/cves/2022/23xxx/CVE-2022-23943.json