cbcvebase.
CVE-2022-23943
published 2022-03-14

CVE-2022-23943: Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

Affected

14 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.4.0 < 2.4.532.4.53
apachehttpd
apache_software_foundationapache_http_server2.4 – 2.4.52
debianapache2< apache2 2.4.53-1 (bookworm)apache2 2.4.53-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_httpd_2.4.53-1_on_cbl_mariner_2.0
msrccm1_httpd_2.4.53-1_on_cbl_mariner_1.0
oraclehttp_server
oraclehttp_server
oraclezfs_storage_appliance_kit
paloaltopan-os

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL