Lucene search

K
cvelistApacheCVELIST:CVE-2022-25147
HistoryJan 31, 2023 - 3:54 p.m.

CVE-2022-25147 Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functions

2023-01-3115:54:51
CWE-190
apache
www.cve.org
12
cve-2022-25147
apache portable runtime utility
out-of-bounds writes
apr_base64 functions
buffer overflow

AI Score

7

Confidence

High

EPSS

0.002

Percentile

55.9%

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer.

This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache Portable Runtime Utility (APR-util)",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "1.6.1",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]