Your submission was sent successfully! Close

CVE-2022-29404

Published: 9 June 2022

In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
apache2
Launchpad, Ubuntu, Debian
bionic
Released (2.4.29-1ubuntu4.24)
focal
Released (2.4.41-4ubuntu3.12)
impish
Released (2.4.48-3.1ubuntu3.5)
jammy
Released (2.4.52-1ubuntu4.1)
kinetic
Released (2.4.54-2ubuntu1)
trusty
Released (2.4.7-1ubuntu4.22+esm6)
upstream
Released (2.4.54-1)
xenial
Released (2.4.18-2ubuntu3.17+esm6)
Patches:
upstream: https://github.com/apache/httpd/commit/1a09953b2439f94714feb03358b793ccbae8a2ca