Lucene search

K
f5F5F5:K58003591
HistoryJul 05, 2022 - 12:00 a.m.

K58003591 : Apache HTTP server vulnerability CVE-2022-28614

2022-07-0500:00:00
my.f5.com
52
apache http server
vulnerability
cve-2022-28614
integer overflow
out-of-bounds read
sensitive information

AI Score

7.2

Confidence

Low

EPSS

0.003

Percentile

71.9%

Security Advisory Description

The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the ‘ap_rputs’ function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue. (CVE-2022-28614)

Impact

A very large input to the ap_rputs andap_rwrite functions can lead to an integer overflow and result in an out-of-bounds read. Integer overflow or wraparound may lead to exposure of sensitive information to an unauthorized actor.