ZeroHour

CVE-2022-23943

CVSS 3.1
9.8 critical
EPSS
50%p99
Published
()
Modified
Description

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

Vendors
apachefedoraprojectdebianoracle
Products
http server, fedora, debian linux, zfs storage appliance kit
Weakness
CWE-190, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news