[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE-2022-28331: Apache Portable Runtime (APR):  Windows out-of-bounds write in apr_so
From:       Eric Covener <covener () apache ! org>
Date:       2023-01-31 15:13:23
Message-ID: 5056c1f3-fe9f-7a08-fdf6-9f90f12505d9 () apache ! org
[Download RAW message or body]

Severity: moderate

Description:

On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based \
buffer in apr_socket_sendv(). This is a result of integer overflow.

Credit:

Ronald Crane (Zippenhop LLC) (finder)

References:

https://apr.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-28331


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic