PT-2023-1354 · Apache+1 · Apache Portable Runtime+1

·

CVE-2022-28331

·

Publicado

2023-01-31

·

Atualizado

2025-12-10

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Portable Runtime versions 1.7.0 and earlier
Description The issue is related to a buffer overflow in the apr socket sendv() function of the Apache Portable Runtime (APR) library on Windows operating systems. This is caused by an integer overflow, allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Apache Portable Runtime versions 1.7.0 and earlier, consider updating to a version later than 1.7.0 to resolve the issue. As a temporary workaround, consider restricting the use of the apr socket sendv() function until a patch is available.

Exploit

Correção

Memory Corruption

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-15436
BDU:2023-00668
BIT-APR-2022-28331
CVE-2022-28331

Produtos afetados

Alt Linux
Apache Portable Runtime