• CVE-2022-28614

发布时间: 2022年6月24日

修改时间: 2024年10月31日

概要

The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the ap_rputs function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue.

CVSS v3 指标

NVD openEuler
Confidentiality Low Low
Attack Vector Network Network
CVSS评分 5.3 5.3
Attack Complexity Low Low
Privileges Required None None
Scope Unchanged Unchanged
Integrity None None
User Interaction None None
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2022-1661 httpd security update 2022年6月24日

影响产品

产品 状态
KY3.4-4A httpd Fixed
KY3.4-5 httpd Fixed
KY3.5.1 httpd Fixed