PT-2022-1925 · Apache+10 · Apache Http Server+10
Ronald Crane
·
Published
2022-03-14
·
Updated
2026-02-17
·
CVE-2022-23943
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server 2.4 versions 2.4.52 and prior versions
Description
The issue is related to an out-of-bounds write vulnerability in the mod sed module of Apache HTTP Server. This vulnerability allows an attacker to overwrite heap memory with possibly attacker-provided data, potentially enabling the execution of arbitrary code. The vulnerability can be exploited remotely.
Recommendations
For Apache HTTP Server 2.4 versions 2.4.52 and prior versions, update to a version later than 2.4.52 to resolve the issue. As a temporary workaround, consider disabling the mod sed module until a patch is available. Restrict access to the mod sed module to minimize the risk of exploitation. Avoid using the mod sed module in the affected API endpoints until the issue is resolved.
Exploit
Fix
Memory Corruption
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu