Lucene search

K
cvelistApacheCVELIST:CVE-2022-24963
HistoryJan 31, 2023 - 3:52 p.m.

CVE-2022-24963 Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions

2023-01-3115:52:09
CWE-190
apache
www.cve.org
7
apache portable runtime
integer overflow
wraparound vulnerability
apr_encode functions

AI Score

9.6

Confidence

High

EPSS

0.084

Percentile

94.5%

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime (APR) version 1.7.0.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache Portable Runtime (APR)",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "1.7.0"
      }
    ]
  }
]