cbcvebase.
CVE-2022-25147
published 2023-01-31

CVE-2022-25147: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of…

medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.

Affected

23 ranges
VendorProductVersion rangeFixed in
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.3-r01.6.3-r0
apacheapr-util>= 0 < 1.6.1-5+deb11u11.6.1-5+deb11u1
apacheapr-util>= 0 < 1.6.3-11.6.3-1
apacheapr-util>= 0 < 1.6.3-11.6.3-1
apacheapr-util>= 0 < 1.6.3-11.6.3-1
apacheportable_runtime_utility<= 1.6.1
apache_software_foundationapache_portable_runtime_utility<= 1.6.1
debianapr-util< apr-util 1.6.3-1 (bookworm)apr-util 1.6.3-1 (bookworm)
msrccbl2_apr-util_1.6.3-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_apr-util_1.6.3-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
osv6.5MEDIUM