7.5
CVSSv3

CVE-2022-22728

Published: 25/08/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A flaw in Apache libapreq2 versions 2.16 and previous versions could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache libapreq2

fedoraproject fedora 35

fedoraproject fedora 36

fedoraproject fedora 37

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #1018191 libapreq2: CVE-2022-22728: multipart form parse memory corruption Package: src:libapreq2; Maintainer for src:libapreq2 is Steinar H Gunderson <sesse@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 26 Aug 2022 19:09:02 UTC Severity: important Tags: secur ...
A flaw in Apache libapreq2 versions 216 and earlier could cause a buffer overflow while processing multipart form uploads A remote attacker could send a request causing a process crash which could lead to a denial of service attack (CVE-2022-22728) ...