CVE-2022-22721
Summary
| CVE | CVE-2022-22721 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-14 11:15:00 UTC |
| Updated | 2023-11-07 03:43:00 UTC |
| Description | If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | All | All | All | All |
| Operating System | Apple | Macos | All | All | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2020-001 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2021-001 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2021-002 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2021-003 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2021-004 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2021-005 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2021-006 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2021-007 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2021-008 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2022-001 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2022-002 | All | All |
| Operating System | Apple | Macos | 10.15.7 | security_update_2022-003 | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2020-001 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-001 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-002 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-003 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-004 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-005 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-006 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-007 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2021-008 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2022-001 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2022-002 | All | All |
| Operating System | Apple | Mac Os X | 10.15.7 | security_update_2022-003 | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.4.0.0 | All | All | All |
| Application | Oracle | Http Server | 12.2.1.3.0 | All | All | All |
| Application | Oracle | Http Server | 12.2.1.4.0 | All | All | All |
| Application | Oracle | Zfs Storage Appliance Kit | 8.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache HTTPD: Multiple Vulnerabilities (GLSA 202208-20) — Gentoo security | GENTOO | security.gentoo.org | |
| [SECURITY] Fedora 36 Update: httpd-2.4.53-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| About the security content of macOS Big Sur 11.6.6 - Apple Support | CONFIRM | support.apple.com | |
| Full Disclosure: APPLE-SA-2022-05-16-2 macOS Monterey 12.4 | FULLDISC | seclists.org | |
| About the security content of macOS Monterey 12.4 - Apple Support | CONFIRM | support.apple.com | |
| Oracle Critical Patch Update Advisory - April 2022 | MISC | www.oracle.com | |
| [SECURITY] [DLA 2960-1] apache2 security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 34 Update: httpd-2.4.53-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| About the security content of Security Update 2022-004 Catalina - Apple Support | CONFIRM | support.apple.com | |
| [SECURITY] Fedora 35 Update: httpd-2.4.53-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| March 2022 Apache HTTP Server Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project | MISC | httpd.apache.org | |
| [SECURITY] Fedora 36 Update: httpd-2.4.53-1.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Full Disclosure: APPLE-SA-2022-05-16-3 macOS Big Sur 11.6.6 | FULLDISC | seclists.org | |
| [SECURITY] Fedora 34 Update: httpd-2.4.53-1.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Full Disclosure: APPLE-SA-2022-05-16-4 Security Update 2022-004 Catalina | FULLDISC | seclists.org | |
| Oracle Critical Patch Update Advisory - July 2022 | N/A | www.oracle.com | |
| [SECURITY] Fedora 35 Update: httpd-2.4.53-1.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| oss-security - CVE-2022-22721: Apache HTTP Server: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody | MLIST | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Anonymous working with Trend Micro Zero Day Initiative
Legacy QID Mappings
- 150515 Apache HTTP Server 2.4.53 Multiple Vulnerabilities
- 160250 Oracle Enterprise Linux Security Update for httpd:2.4 (ELSA-2022-7647)
- 160309 Oracle Enterprise Linux Security Update for httpd (ELSA-2022-8067)
- 179151 Debian Security Update for apache2 (DLA 2960-1)
- 179200 Debian Security Update for apache2 (CVE-2022-22721)
- 198705 Ubuntu Security Notification for Apache Hypertext Transfer Protocol (HTTP) Server Vulnerabilities (USN-5333-1)
- 240698 Red Hat Update for httpd24-httpd (RHSA-2022:6753)
- 240854 Red Hat Update for httpd:2.4 (RHSA-2022:7647)
- 240885 Red Hat Update for httpd security (RHSA-2022:8067)
- 240996 Red Hat Update for JBoss Core Services (RHSA-2022:8840)
- 282500 Fedora Security Update for httpd (FEDORA-2022-b4103753e9)
- 282521 Fedora Security Update for httpd (FEDORA-2022-21264ec6db)
- 296057 Oracle Solaris 11.4 Support Repository Update (SRU) 44.113.4 Missing (bulletinapr2022)
- 353269 Amazon Linux Security Advisory for httpd : ALAS2-2022-1783
- 353274 Amazon Linux Security Advisory for httpd24 : ALAS-2022-1584
- 354481 Amazon Linux Security Advisory for httpd : ALAS2022-2022-053
- 354482 Amazon Linux Security Advisory for httpd : ALAS2022-2022-202
- 354577 Amazon Linux Security Advisory for httpd : ALAS2022-2022-202
- 355264 Amazon Linux Security Advisory for httpd : ALAS2023-2023-072
- 376607 Apple macOS Security Update 2022-004 Catalina (HT213255)
- 376608 Apple MacOS Big Sur 11.6.6 Not Installed (HT213256)
- 376612 Apple macOS Monterey 12.4 Not Installed (HT213257)
- 376865 IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6565413)
- 377911 Oracle Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (CPUJAN2023)
- 378363 IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6565413)
- 500026 Alpine Linux Security Update for apache2
- 503717 Alpine Linux Security Update for apache2
- 671578 EulerOS Security Update for httpd (EulerOS-SA-2022-1569)
- 671659 EulerOS Security Update for httpd (EulerOS-SA-2022-1730)
- 671739 EulerOS Security Update for httpd (EulerOS-SA-2022-1790)
- 671758 EulerOS Security Update for httpd (EulerOS-SA-2022-1807)
- 671800 EulerOS Security Update for httpd (EulerOS-SA-2022-1843)
- 671812 EulerOS Security Update for httpd (EulerOS-SA-2022-1867)
- 671851 EulerOS Security Update for httpd (EulerOS-SA-2022-1893)
- 690812 Free Berkeley Software Distribution (FreeBSD) Security Update for apache httpd (6601c08d-a46c-11ec-8be6-d4c9ef517024)
- 710595 Gentoo Linux Apache HTTPD Multiple Vulnerabilities (GLSA 202208-20)
- 730403 Apache Hypertext Transfer Protocol (HTTP) Server Out-of-bounds Write Vulnerability
- 751909 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:0928-1)
- 751912 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:0918-1)
- 751918 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:0929-1)
- 751936 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:1031-1)
- 751942 OpenSUSE Security Update for apache2 (openSUSE-SU-2022:1031-1)
- 753400 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:14924-1)
- 900756 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (9007)
- 901606 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (9017-1)
- 940741 AlmaLinux Security Update for httpd:2.4 (ALSA-2022:7647)
- 940823 AlmaLinux Security Update for httpd (ALSA-2022:8067)
- 960175 Rocky Linux Security Update for httpd:2.4 (RLSA-2022:7647)
- 960481 Rocky Linux Security Update for httpd (RLSA-2022:8067)