PT-2022-1925 · Apache+10 · Apache Http Server+10

Ronald Crane

·

Published

2022-03-14

·

Updated

2026-02-17

·

CVE-2022-23943

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server 2.4 versions 2.4.52 and prior versions
Description The issue is related to an out-of-bounds write vulnerability in the mod sed module of Apache HTTP Server. This vulnerability allows an attacker to overwrite heap memory with possibly attacker-provided data, potentially enabling the execution of arbitrary code. The vulnerability can be exploited remotely.
Recommendations For Apache HTTP Server 2.4 versions 2.4.52 and prior versions, update to a version later than 2.4.52 to resolve the issue. As a temporary workaround, consider disabling the mod sed module until a patch is available. Restrict access to the mod sed module to minimize the risk of exploitation. Avoid using the mod sed module in the affected API endpoints until the issue is resolved.

Exploit

Fix

Memory Corruption

Integer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2022:7647
ALSA-2022:8067
ALT-PU-2022-1522
ALT-PU-2022-1553
ALT-PU-2022-1574
ALT-PU-2022-1602
AZL-9018
BDU:2022-01461
BIT-APACHE-2022-23943
CESA-2022_7647
CVE-2022-23943
DLA-2960-1
MGASA-2022-0105
OESA-2022-1596
OPENSUSE-SU-2022:1031-1
OPENSUSE-SU-2022_1031-1
OPENSUSE-SU-2024:11919-1
RHSA-2022:6753
RHSA-2022:7647
RHSA-2022:8067
RHSA-2022:8840
RHSA-2022_7647
RHSA-2022_8067
RLSA-2022:7647
RLSA-2022:8067
SUSE-SU-2022:0918-1
SUSE-SU-2022:0928-1
SUSE-SU-2022:0929-1
SUSE-SU-2022:1031-1
USN-5333-1
USN-5333-2

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu