CVE-2023-31122
published 2023-10-23CVE-2023-31122: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.98%
85.8th percentile
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 2.4.58 | 2.4.58 |
| apache_software_foundation | apache_http_server | <= 2.4.57 | — |
| debian | apache2 | < apache2 2.4.59-1~deb12u1 (bookworm) | apache2 2.4.59-1~deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy Service Suite
cisa_ics·2025-05-13·CVSS 9.8
[CRITICAL] Hitachi Energy Service Suite
ICS Advisory
##
Hitachi Energy Service Suite
Release DateMay 13, 2025
Alert CodeICSA-25-133-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Service Suite
- Vulnerabilities: Use of Less Trusted Source, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Integer Overflow or Wraparound, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Exposure of Sensitive Information to an Unauthorized Actor, Memory Allocation with Excessive Size Value, Out-of-bounds Read, Uncontrolled Resource Consumption, Improper Resource Shutdown or Re
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
Oracle
Oracle Oracle Communications Risk Matrix: Security (Apache HTTP Server) — CVE-2023-31122
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2023-31122 [HIGH] Oracle Oracle Communications Risk Matrix: Security (Apache HTTP Server) — CVE-2023-31122
Oracle Oracle Communications Risk Matrix: Security (Apache HTTP Server) vulnerability
CVE: CVE-2023-31122
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2023-31122
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2023-31122 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2023-31122
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) vulnerability
CVE: CVE-2023-31122
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Ubuntu
Apache HTTP Server vulnerability
vendor_ubuntu·2023-11-23
CVE-2023-31122 Apache HTTP Server vulnerability
Title: Apache HTTP Server vulnerability
Summary: Apache HTTP Server could be made to crash if it received a specially
crafted request.
David Shoon discovered that the Apache HTTP Server mod_macro module
incorrectly handled certain memory operations. A remote attacker could
possibly use this issue to cause the server to crash, resulting in a denial
of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2023-11-22·CVSS 7.5
CVE-2023-45802 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
David Shoon discovered that the Apache HTTP Server mod_macro module
incorrectly handled certain memory operations. A remote attacker could
possibly use this issue to cause the server to crash, resulting in a denial
of service. (CVE-2023-31122)
Prof. Sven Dietrich, Isa Jafarov, Prof. Heejo Lee, and Choongin Lee
discovered that the Apache HTTP Server incorrectly handled certain HTTP/2
connections. A remote attacker could possibly use this issue to cause the
server to consume resources, leading to a denial of service. This issue
only affected Ubuntu 23.04, and Ubuntu 23.10. (CVE-2023-43622)
Will Dormann and David Warren discovered that the Apache HTTP Server
incorrectly handled mem
Red Hat
httpd: mod_macro: out-of-bounds read vulnerability
vendor_redhat·2023-10-19·CVSS 7.5
CVE-2023-31122 [HIGH] CWE-125 httpd: mod_macro: out-of-bounds read vulnerability
httpd: mod_macro: out-of-bounds read vulnerability
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
A flaw was found in the mod_macro module of httpd. When processing a very long macro, the null byte terminator will not be added, leading to an out-of-bounds read, resulting in a crash.
Statement: This flaw only affects configurations with mod_macro loaded and when a very long macro is configured and used, specifically a macro longer than 8191 characters. If these conditions are not present, the server is not affected and no further mitigation is needed. For more information about the mitigation, see the mitigation section below.
The httpd mod_macro module is enabled by default in Red Hat Enterprise Linux 8, 9, and
Debian
CVE-2023-31122: apache2 - Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue a...
vendor_debian·2023·CVSS 7.5
CVE-2023-31122 [HIGH] CVE-2023-31122: apache2 - Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue a...
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
Scope: local
bookworm: resolved (fixed in 2.4.59-1~deb12u1)
bullseye: resolved (fixed in 2.4.59-1~deb11u1)
forky: resolved (fixed in 2.4.58-1)
sid: resolved (fixed in 2.4.58-1)
trixie: resolved (fixed in 2.4.58-1)
OSV
apache2 vulnerabilities
osv·2023-11-22·CVSS 7.5
CVE-2023-31122 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
David Shoon discovered that the Apache HTTP Server mod_macro module
incorrectly handled certain memory operations. A remote attacker could
possibly use this issue to cause the server to crash, resulting in a denial
of service. (CVE-2023-31122)
Prof. Sven Dietrich, Isa Jafarov, Prof. Heejo Lee, and Choongin Lee
discovered that the Apache HTTP Server incorrectly handled certain HTTP/2
connections. A remote attacker could possibly use this issue to cause the
server to consume resources, leading to a denial of service. This issue
only affected Ubuntu 23.04, and Ubuntu 23.10. (CVE-2023-43622)
Will Dormann and David Warren discovered that the Apache HTTP Server
incorrectly handled memory when handling HTTP/2 connections. A remote
attacker could possibly use this issue
OSV
CVE-2023-31122: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server
osv·2023-10-23·CVSS 7.5
CVE-2023-31122 [HIGH] CVE-2023-31122: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
GHSA
GHSA-xw7g-pw64-xph3: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server
ghsa_unreviewed·2023-10-23
CVE-2023-31122 [HIGH] CWE-125 GHSA-xw7g-pw64-xph3: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
No detection rules found.
No public exploits indexed.
https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/TI3V2YCEUM65QDYPGGNUZ7UONIM5OEXC/https://lists.fedoraproject.org/archives/list/[email protected]/message/VZJTT5TEFNSBWVMKCLS6EZ7PI6EJYBCO/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZFDNHDH4VLFGDPY6MEZV2RO5N5FLFONW/https://security.netapp.com/advisory/ntap-20231027-0011/https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/TI3V2YCEUM65QDYPGGNUZ7UONIM5OEXC/https://lists.fedoraproject.org/archives/list/[email protected]/message/VZJTT5TEFNSBWVMKCLS6EZ7PI6EJYBCO/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZFDNHDH4VLFGDPY6MEZV2RO5N5FLFONW/https://security.netapp.com/advisory/ntap-20231027-0011/
2023-10-23
Published