PT-2022-15648 · Apache · Apache Libapreq2
Joe Orton
·
Published
2022-08-25
·
Updated
2023-05-03
·
CVE-2022-22728
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache libapreq2 versions 2.16 and earlier
Description
A flaw in Apache libapreq2 could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash, which could lead to a denial of service attack.
Recommendations
For Apache libapreq2 versions 2.16 and earlier, consider updating to a version later than 2.16 to resolve the issue. As a temporary workaround, consider restricting access to multipart form uploads to minimize the risk of exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Libapreq2