Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://httpd.apache.org/security/vulnerabilities_24.html | vendor advisory |
http://www.openwall.com/lists/oss-security/2022/06/08/7 | third party advisory mailing list |
https://security.netapp.com/advisory/ntap-20220624-0005/ | third party advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/ | third party advisory vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/ | third party advisory vendor advisory |
https://security.gentoo.org/glsa/202208-20 | third party advisory vendor advisory |