oss-sec mailing list archives

CVE-2022-28614: Apache HTTP Server: read beyond bounds via ap_rwrite()


From: Stefan Eissing <icing () apache org>
Date: Wed, 08 Jun 2022 09:43:25 +0000

Severity: low

Description:

The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause 
the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function.

Credit:

The Apache HTTP Server project would like to thank Ronald Crane (Zippenhop LLC) for reporting this issue

References:

https://httpd.apache.org/security/vulnerabilities_24.html


Current thread: