CVE-2022-24963: Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions

Eric Covener <[email protected]>
Newsgroups gmane.comp.apache.apr.devel
Message-ID <[email protected]>
Severity: moderate

Description:

Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer.
This issue affects Apache Portable Runtime (APR) version 1.7.0.

Credit:

Ronald Crane (Zippenhop LLC) (finder)

References:

https://apr.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-24963
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.