CVE-2023-31122: Apache HTTP Server: mod_macro buffer over-read
Out-of-bounds Read vulnerability in modmacro of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.57.
References: https://httpd.apache.org/security/vulnerabilities24.html#CVE-2023-31122 https://www.openwall.com/lists/oss-security/2023/10/19/4
Upstream patch: https://svn.apache.org/viewvc?view=revision&revision=1912993
Other sources
Out-of-bounds Read vulnerability in modmacro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/apache2to a version that resolves this vulnerability.Fixed in 2.4.29-1ubuntu4.27+ - Upgrade
Upgrade
ubuntu/apache2to a version that resolves this vulnerability.Fixed in 2.4.41-4ubuntu3.15 - Upgrade
Upgrade
ubuntu/apache2to a version that resolves this vulnerability.Fixed in 2.4.52-1ubuntu4.7 - Upgrade
Upgrade
ubuntu/apache2to a version that resolves this vulnerability.Fixed in 2.4.55-1ubuntu2.1 - Upgrade
Upgrade
ubuntu/apache2to a version that resolves this vulnerability.Fixed in 2.4.57-2ubuntu2.1 - Upgrade
Upgrade
ubuntu/apache2to a version that resolves this vulnerability.Fixed in 2.4.7-1ubuntu4.22+ - Upgrade
Upgrade
ubuntu/apache2to a version that resolves this vulnerability.Fixed in 2.4.58-1 - Upgrade
Upgrade
ubuntu/apache2to a version that resolves this vulnerability.Fixed in 2.4.18-2ubuntu3.17+ - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.59-1~deb11u1Fixed in 2.4.59-1~deb12u1Fixed in 2.4.58-1Fixed in 2.4.59-1 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.58
Event History
Frequently Asked Questions
What is CVE-2023-31122?
CVE-2023-31122 is an out-of-bounds read vulnerability in mod_macro of Apache HTTP Server.
Which versions of Apache HTTP Server are affected by CVE-2023-31122?
CVE-2023-31122 affects Apache HTTP Server versions up to and including 2.4.57.
What is the severity of CVE-2023-31122?
The severity of CVE-2023-31122 is high with a CVSS score of 7.5.
How can I fix CVE-2023-31122?
To fix CVE-2023-31122, upgrade Apache HTTP Server to a version beyond 2.4.57.
Are there any references for CVE-2023-31122?
Yes, you can find references for CVE-2023-31122 at the following links: 1. [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) 2. [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TI3V2YCEUM65QDYPGGNUZ7UONIM5OEXC/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TI3V2YCEUM65QDYPGGNUZ7UONIM5OEXC/) 3. [https://security.netapp.com/advisory/ntap-20231027-0011/](https://security.netapp.com/advisory/ntap-20231027-0011/)