CVE-2022-24963

Name
CVE-2022-24963
Description
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://lists.apache.org/thread/fw9p6sdncwsjkstwc066vz57xqzfksq9
MISC https://security.netapp.com/advisory/ntap-20230908-0008/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:apache:portable_runtime:1.7.0:*:*:*:*:*:*:* portable_runtime == None == 1.7.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
apr edge-main 1.7.1-r0 None fixed
apr 3.22-main 1.7.1-r0 None fixed
apr 3.21-main 1.7.1-r0 None fixed
apr 3.20-main 1.7.1-r0 None fixed
apr 3.19-main 1.7.1-r0 None fixed
apr 3.18-main 1.7.1-r0 None fixed
apr 3.17-main 1.7.1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed