PT-2022-3344 · Apache+2 · Apache Http Server+2

Ronald Crane

·

Published

2022-06-08

·

Updated

2025-05-15

·

CVE-2022-28330

CVSS v2.0

6.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.53 and earlier
Description The issue is related to a buffer overflow condition in the mod isapi module of the Apache HTTP Server. Exploitation of this issue may allow a remote attacker to cause a denial of service by sending a specially crafted HTTP request. The vulnerability can also lead to reading beyond the bounds of a buffer, potentially allowing an attacker to read memory contents or cause a denial of service.
Recommendations For Apache HTTP Server versions 2.4.53 and earlier, consider disabling the mod isapi module as a temporary workaround until a patch is available. Restrict access to the mod isapi module to minimize the risk of exploitation. Avoid using the mod isapi module in production environments until the issue is resolved.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2087
ALT-PU-2022-2093
ALT-PU-2022-2095
ALT-PU-2023-1260
BDU:2022-04101
BIT-APACHE-2022-28330
CVE-2022-28330
OESA-2022-1784
OPENSUSE-SU-2024:12142-1

Affected Products

Alt Linux
Apache Http Server
Red Os