Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-22728
HistoryAug 25, 2022 - 12:00 a.m.

CVE-2022-22728

2022-08-2500:00:00
ubuntu.com
ubuntu.com
17
apache
libapreq2
buffer overflow
form uploads
denial of service

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.029 Low

EPSS

Percentile

90.8%

A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer
overflow while processing multipart form uploads. A remote attacker could
send a request causing a process crash which could lead to a denial of
service attack.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.029 Low

EPSS

Percentile

90.8%