Your submission was sent successfully! Close

CVE-2022-30556

Published: 9 June 2022

Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
apache2
Launchpad, Ubuntu, Debian
bionic
Released (2.4.29-1ubuntu4.24)
focal
Released (2.4.41-4ubuntu3.12)
impish
Released (2.4.48-3.1ubuntu3.5)
jammy
Released (2.4.52-1ubuntu4.1)
kinetic
Released (2.4.54-2ubuntu1)
trusty
Released (2.4.7-1ubuntu4.22+esm8)
upstream
Released (2.4.54-1)
xenial
Released (2.4.18-2ubuntu3.17+esm6)
Patches:
upstream: https://github.com/apache/httpd/commit/11a3fcbf9e64239d8fe8402d941bbdcbc4532c88