oss-sec mailing list archives
CVE-2022-30556: Apache HTTP Server: Information Disclosure in mod_lua with websockets
From: Stefan Eissing <icing () apache org>
Date: Wed, 08 Jun 2022 09:43:54 +0000
Severity: low Description: Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer. Credit: The Apache HTTP Server project would like to thank Ronald Crane (Zippenhop LLC) for reporting this issue References: https://httpd.apache.org/security/vulnerabilities_24.html
Current thread:
- CVE-2022-30556: Apache HTTP Server: Information Disclosure in mod_lua with websockets Stefan Eissing (Jun 08)