Related Vulnerabilities: CVE-2022-22721  

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

Description

The MITRE CVE dictionary describes this issue as:

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

Additional Information

  • Bugzilla 2064320: CVE-2022-22721 httpd: Apache Core Possible buffer overflow with very large or unlimited LimitXMLRequestBody
  • CWE-190: Integer Overflow or Wraparound
  • FAQ: Frequently asked questions about CVE-2022-22721