CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2022-24963

CVSS 9.8v3.1pub. 2023-01-31upd. 2025-03-27

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Portable Runtime

    APP
    Apache
    1.7.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2022-28331CRITICAL9.8PL ✓same product

Buffer overflow w Apache Portable Runtime na Windows — integer overflow w apr_socket_sendv()

CVE-2021-35940HIGH7.1same product

An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 re...

CVE-2017-12613HIGH7.1same product

When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache P...

CVE-2009-2699HIGH7.5same product

The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR)...

CVE-2009-2412HIGH10.0same product

Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility librar...