CVE-2022-23943: mod_sed: Read/write beyond bounds
An out-of-bounds read/write vulnerability was found in the modsed module of httpd. This flaw allows an attacker to overwrite the memory of an httpd instance that is using modsed with data provided by the attacker.
Other sources
Out-of-bounds Write vulnerability in modsed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.51-37.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.51-37.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.53-7.el9 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-23.el7.5 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.53 - Configuration
Disable the mod_sed module and restart httpd to mitigate the out-of-bounds read/write vulnerability.
Apache httpd (mod_sed) mod_sed = disabled - Compensating control
If disabling mod_sed is not immediately possible, ensure the httpd instance is not using mod_sed, since the flaw affects Apache HTTP Server 2.4.52 and prior versions when mod_sed is enabled.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-23943?
CVE-2022-23943 is an out-of-bounds read/write vulnerability found in the mod_sed module of Apache HTTP Server.
How does CVE-2022-23943 impact Apache HTTP Server?
CVE-2022-23943 allows an attacker to overwrite heap memory with possibly attacker-provided data.
What versions of Apache HTTP Server are affected by CVE-2022-23943?
Apache HTTP Server versions 2.4.52 and prior versions are affected by CVE-2022-23943.
What is the severity of CVE-2022-23943?
CVE-2022-23943 has a severity rating of critical (9.8).
How can I fix CVE-2022-23943?
To fix CVE-2022-23943, update Apache HTTP Server to version 2.4.53 or later.