PT-2022-1919 · Apache+11 · Apache Http Server+11
Published
2022-03-14
·
Updated
2025-03-22
·
CVE-2022-22721
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.52 and earlier
Description
The issue is related to an integer overflow that occurs when the LimitXMLRequestBody is set to allow request bodies larger than 350MB on 32-bit systems, which later causes out of bounds writes. This can potentially allow a remote attacker to execute arbitrary code. The vulnerability is associated with a buffer overflow in memory and can lead to memory damage and arbitrary code execution on the target system.
Recommendations
For Apache HTTP Server versions 2.4.52 and earlier, update to version 2.4.53 to resolve the issue.
As a temporary workaround, consider setting the LimitXMLRequestBody to a value that does not exceed 350MB on 32-bit systems to minimize the risk of exploitation.
Exploit
Fix
Integer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu