CVE-2022-22728
published 2022-08-25CVE-2022-22728: A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.71%
90.8th percentile
A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | libapreq2 | <= 2.16 | — |
| apache | libapreq2 | >= 0 < 2.13-7+deb11u1 | 2.13-7+deb11u1 |
| apache | libapreq2 | >= 0 < 2.17-1 | 2.17-1 |
| apache | libapreq2 | >= 0 < 2.17-1 | 2.17-1 |
| apache_software_foundation | libapreq2 | unspecified – 2.16 | — |
| debian | debian_linux | — | — |
| debian | libapreq2 | < libapreq2 2.13-7+deb11u1 (bullseye) | libapreq2 2.13-7+deb11u1 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache libapreq2 up to 2.16 Multipart Form buffer overflow (FEDORA-2022-61f5b492b7 / EUVD-2022-27871)
vuldb·2026-04-28·CVSS 7.5
CVE-2022-22728 [HIGH] Apache libapreq2 up to 2.16 Multipart Form buffer overflow (FEDORA-2022-61f5b492b7 / EUVD-2022-27871)
A vulnerability, which was classified as critical, has been found in Apache libapreq2 up to 2.16. This issue affects some unknown processing of the component Multipart Form Handler. This manipulation causes buffer overflow.
This vulnerability is registered as CVE-2022-22728. Remote exploitation of the attack is possible. No exploit is available.
GHSA
GHSA-jq3x-hcjw-4j6x: A flaw in Apache libapreq2 versions 2
ghsa_unreviewed·2022-08-26
CVE-2022-22728 [HIGH] CWE-120 GHSA-jq3x-hcjw-4j6x: A flaw in Apache libapreq2 versions 2
A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
OSV
CVE-2022-22728: A flaw in Apache libapreq2 versions 2
osv·2022-08-25·CVSS 7.5
CVE-2022-22728 [HIGH] CVE-2022-22728: A flaw in Apache libapreq2 versions 2
A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
Debian
CVE-2022-22728: libapreq2 - A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overfl...
vendor_debian·2022·CVSS 7.5
CVE-2022-22728 [HIGH] CVE-2022-22728: libapreq2 - A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overfl...
A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
Scope: local
bullseye: resolved (fixed in 2.13-7+deb11u1)
forky: resolved (fixed in 2.17-1)
sid: resolved (fixed in 2.17-1)
trixie: resolved (fixed in 2.17-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/08/25/3http://www.openwall.com/lists/oss-security/2022/08/25/4http://www.openwall.com/lists/oss-security/2022/08/26/4http://www.openwall.com/lists/oss-security/2022/12/29/1http://www.openwall.com/lists/oss-security/2022/12/30/4http://www.openwall.com/lists/oss-security/2022/12/31/1http://www.openwall.com/lists/oss-security/2022/12/31/5http://www.openwall.com/lists/oss-security/2023/01/02/1http://www.openwall.com/lists/oss-security/2023/01/02/2http://www.openwall.com/lists/oss-security/2023/01/03/2https://lists.apache.org/thread/2fsjoor96d47vtkpf76x4yo06nccvy1yhttps://lists.debian.org/debian-lts-announce/2023/01/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PUUS3JL44UUSLJTSXE46HVKZIW7E7PE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HZZKVHYYWACPWONPEFRNPIRE3HYLV4T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BE5MEHGIQUEIISBCVHM43IN2NBDXBFOJ/https://security.gentoo.org/glsa/202305-20http://www.openwall.com/lists/oss-security/2022/08/25/3http://www.openwall.com/lists/oss-security/2022/08/25/4http://www.openwall.com/lists/oss-security/2022/08/26/4http://www.openwall.com/lists/oss-security/2022/12/29/1http://www.openwall.com/lists/oss-security/2022/12/30/4http://www.openwall.com/lists/oss-security/2022/12/31/1http://www.openwall.com/lists/oss-security/2022/12/31/5http://www.openwall.com/lists/oss-security/2023/01/02/1http://www.openwall.com/lists/oss-security/2023/01/02/2http://www.openwall.com/lists/oss-security/2023/01/03/2https://lists.apache.org/thread/2fsjoor96d47vtkpf76x4yo06nccvy1yhttps://lists.debian.org/debian-lts-announce/2023/01/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PUUS3JL44UUSLJTSXE46HVKZIW7E7PE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HZZKVHYYWACPWONPEFRNPIRE3HYLV4T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BE5MEHGIQUEIISBCVHM43IN2NBDXBFOJ/https://security.gentoo.org/glsa/202305-20
2022-08-25
Published