Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-24963
HistoryJan 31, 2023 - 12:00 a.m.

CVE-2022-24963

2023-01-3100:00:00
ubuntu.com
ubuntu.com
19
cve-2022-24963
apache portable runtime
integer overflow
vulnerability
apr_encode functions
buffer
bounds
apache portable runtime version 1.7.0

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.084

Percentile

94.5%

Integer Overflow or Wraparound vulnerability in apr_encode functions of
Apache Portable Runtime (APR) allows an attacker to write beyond bounds of
a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

Notes

Author Note
rodrigo-zaiden apr_encode_* API, which contains the affected code was added in version 1.7.0, so earlier version than that are not affected.
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchapr< 1.7.0-8ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchapr< 1.7.0-8ubuntu0.22.10.1UNKNOWN

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.084

Percentile

94.5%