CVE-2022-28330

Name
CVE-2022-28330
Description
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MLIST http://www.openwall.com/lists/oss-security/2022/06/08/3
MISC https://httpd.apache.org/security/vulnerabilities_24.html
CONFIRM https://security.netapp.com/advisory/ntap-20220624-0005/

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
apache2 edge-main 2.4.54-r0 Kaarle Ritvanen <kunkku@alpinelinux.org> fixed
apache2 3.22-main 2.4.54-r0 None fixed
apache2 3.21-main 2.4.54-r0 None fixed
apache2 3.20-main 2.4.54-r0 None fixed
apache2 3.19-main 2.4.54-r0 None fixed
apache2 3.18-main 2.4.54-r0 None fixed
apache2 3.17-main 2.4.54-r0 None fixed