CVE-2022-24963: Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions
Integer Overflow or Wraparound vulnerability in aprencode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Portable Runtime (APR)to a version that resolves this vulnerability.Fixed in 1.7.0
Event History
Frequently Asked Questions
What is CVE-2022-24963?
CVE-2022-24963 is an Integer Overflow or Wraparound vulnerability in the apr_encode functions of Apache Portable Runtime (APR) that allows an attacker to write beyond the bounds of a buffer.
Which version of Apache Portable Runtime (APR) is affected by CVE-2022-24963?
Apache Portable Runtime (APR) version 1.7.0 is affected by CVE-2022-24963.
What is the severity of CVE-2022-24963?
CVE-2022-24963 has a severity rating of critical, with a CVSS score of 9.8.
How can an attacker exploit CVE-2022-24963?
An attacker can exploit CVE-2022-24963 by leveraging the Integer Overflow or Wraparound vulnerability in the apr_encode functions of Apache Portable Runtime (APR) to write beyond the bounds of a buffer, potentially leading to remote code execution or denial of service.
Is there a fix available for CVE-2022-24963?
Yes, a fix is available for CVE-2022-24963. It is recommended to upgrade to a version of Apache Portable Runtime (APR) that is not affected by this vulnerability.