QID 730403
Date Published: 2022-03-21
QID 730403: Apache Hypertext Transfer Protocol (HTTP) Server Out-of-bounds Write Vulnerability
Apache HTTP Server is a free and open-source cross-platform web server software, released under the terms of Apache License 2.0.
CVE-2022-22719 - A carefully crafted request body can cause a read to a random memory area which could cause the process to crash.
CVE-2022-22720 - Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
CVE-2022-22721 - If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes.
CVE-2022-23943 - Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data.
Affected Versions:
Apache HTTP Server 2.4 - 2.4.52
Successful exploitation of the vulnerability may allow an attacker to redirect victim to a malicious server.
- Apache Security Advisory -
httpd.apache.org/security/vulnerabilities_24.html
CVEs related to QID 730403
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Security Advisory |
|