CVE-2022-28615: Read beyond bounds in ap_strcmp_match()
An out-of-bounds read vulnerability was found in httpd. A very large input to the apstrcmpmatch function can lead to an integer overflow and result in an out-of-bounds read.
Other sources
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in apstrcmpmatch() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use apstrcmpmatch() may hypothetically be affected.
Apache HTTP Server could allow a remote attacker to obtain sensitive information, caused by a read beyond bounds in apstrcmpmatch() when provided with an extremely large input buffer. An attacker could exploit this vulnerability to crash or disclose information.
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-28615?
CVE-2022-28615 is an out-of-bounds read vulnerability in Apache HTTP Server, which may result in a crash or information disclosure.
What is the severity of CVE-2022-28615?
The severity of CVE-2022-28615 is critical with a CVSS score of 9.1.
Which versions of Apache HTTP Server are affected by CVE-2022-28615?
Apache HTTP Server 2.4.53 and earlier versions are affected by CVE-2022-28615.
How can this vulnerability be fixed?
To fix CVE-2022-28615, update to Apache HTTP Server version 2.4.54 or later.
Where can I find more information about CVE-2022-28615?
You can find more information about CVE-2022-28615 on the Apache HTTP Server security vulnerabilities page, the OSS-Security mailing list, and the Red Hat Bugzilla.