PT-2022-3344 · Apache+2 · Apache Http Server+2
Ronald Crane
·
Published
2022-06-08
·
Updated
2025-05-15
·
CVE-2022-28330
CVSS v2.0
6.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.53 and earlier
Description
The issue is related to a buffer overflow condition in the mod isapi module of the Apache HTTP Server. Exploitation of this issue may allow a remote attacker to cause a denial of service by sending a specially crafted HTTP request. The vulnerability can also lead to reading beyond the bounds of a buffer, potentially allowing an attacker to read memory contents or cause a denial of service.
Recommendations
For Apache HTTP Server versions 2.4.53 and earlier, consider disabling the mod isapi module as a temporary workaround until a patch is available. Restrict access to the mod isapi module to minimize the risk of exploitation. Avoid using the mod isapi module in production environments until the issue is resolved.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Http Server
Red Os