Fwd: CVE-2022-25147: Apache Portable Runtime (APR): out-of-bounds writes in the apr_base64 family of functions

Eric Covener <[email protected]>
Newsgroups gmane.comp.apache.apr.devel
Message-ID <CALK=YjNDN8G73FbupBd8CbZLENoepAqy-z49HNcbSe-M5Oqa_Q@mail.gmail.com>
---------- Forwarded message ---------
From: Eric Covener <[email protected]>
Date: Tue, Jan 31, 2023 at 10:13 AM
Subject: CVE-2022-25147: Apache Portable Runtime (APR): out-of-bounds
writes in the apr_base64 family of functions
To: <[email protected]>, <[email protected]>


Severity: moderate

Description:

Integer Overflow or Wraparound vulnerability in apr_base64 functions
of Apache Portable Runtime Utility (APR-util) allows an attacker to
write beyond bounds of a buffer.\nThis issue affects Apache Portable
Runtime Utility (APR-util) 1.6.1 and prior versions.

Credit:

Ronald Crane (Zippenhop LLC) (reporter)

References:

https://apr.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-25147



-- 
Eric Covener
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.