REDHAT-BUG-2172556: Integer Overflow
Published Feb 22, 2023
·Updated
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in aprsocketsendv(). This is a result of integer overflow.
https://lists.apache.org/thread/5pfdfn7h0vsdo5xzjn97vghp0x42jj2r
Affected Software
1 affected component
Apache Portable Runtime<1.7.0
Event History
Feb 22, 2023
Data Sourced
via Red Hat·02:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2172556?
The severity of REDHAT-BUG-2172556 is classified as high due to potential stack corruption resulting from an integer overflow.
2
How do I fix REDHAT-BUG-2172556?
To fix REDHAT-BUG-2172556, upgrade Apache Portable Runtime to version 1.7.1 or later.
3
What are the potential impacts of exploiting REDHAT-BUG-2172556?
Exploiting REDHAT-BUG-2172556 could lead to arbitrary code execution and compromise system integrity.
4
Which versions of Apache Portable Runtime are affected by REDHAT-BUG-2172556?
Apache Portable Runtime versions up to and including 1.7.0 are affected by REDHAT-BUG-2172556.
5
Is there a known workaround for REDHAT-BUG-2172556?
There is no known workaround for REDHAT-BUG-2172556 other than upgrading to a patched version.