PT-2022-1919 · Apache+11 · Apache Http Server+11

Published

2022-03-14

·

Updated

2025-03-22

·

CVE-2022-22721

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.52 and earlier
Description The issue is related to an integer overflow that occurs when the LimitXMLRequestBody is set to allow request bodies larger than 350MB on 32-bit systems, which later causes out of bounds writes. This can potentially allow a remote attacker to execute arbitrary code. The vulnerability is associated with a buffer overflow in memory and can lead to memory damage and arbitrary code execution on the target system.
Recommendations For Apache HTTP Server versions 2.4.52 and earlier, update to version 2.4.53 to resolve the issue. As a temporary workaround, consider setting the LimitXMLRequestBody to a value that does not exceed 350MB on 32-bit systems to minimize the risk of exploitation.

Exploit

Fix

Integer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7647
ALSA-2022:8067
ALT-PU-2022-1522
ALT-PU-2022-1553
ALT-PU-2022-1574
ALT-PU-2022-1602
AZL-9017
BDU:2022-01455
BIT-APACHE-2022-22721
CESA-2022_7647
CVE-2022-22721
DLA-2960-1
MGASA-2022-0105
OESA-2022-1596
OPENSUSE-SU-2022:1031-1
OPENSUSE-SU-2022_1031-1
OPENSUSE-SU-2024:11919-1
RHSA-2022:6753
RHSA-2022:7647
RHSA-2022:8067
RHSA-2022:8840
RHSA-2022_7647
RHSA-2022_8067
RLSA-2022:7647
RLSA-2022:8067
SUSE-SU-2022:0918-1
SUSE-SU-2022:0928-1
SUSE-SU-2022:0929-1
SUSE-SU-2022:1031-1
SUSE-SU-2022:14924-1
SUSE-SU-2022_14924-1
USN-5333-1
USN-5333-2
ZDI-22-876

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu