Out-of-bounds read in Apache HTTP Server - CVE-2022-28330
Published: June 8, 2022 / Updated: October 2, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition with the mod_isapi module. A remote attacker can send a specially crafted HTTP request to the server, trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.
Note, only Windows installations are affected by this vulnerability.
Affected software
Amazon Linux AMI
QuTScloud
Slackware Linux
openEuler
QuTS hero
PowerScale OneFS
JBoss Core Services
QNAP QTS
IBM Aspera Faspex for Linux
IBM Aspera Faspex for Windows
IBM Rational Build Forge
IBM Aspera Orchestrator
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
httpd-debugsource
mod_ldap
httpd-debuginfo
mod_proxy_html
httpd-tools
httpd
mod_ssl
mod_md
mod_session
httpd-devel
httpd-filesystem
httpd-help
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
Maximo Application Suite - IoT Component
How to mitigate CVE-2022-28330
JBoss Core Services - update to 2.4.51 SP1
QNAP QTS - addressed in versions 4.5.4.2125 20220810, 5.0.0.2131 20220815
IBM Aspera Faspex for Linux - update to 4.4.2 PL2
IBM Aspera Faspex for Windows - update to 4.4.2 PL2
IBM Rational Build Forge - update to 8.0.0.23
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-32.el7jbcs, 0.4.10-32.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-17.el7jbcs, 1.0.0-17.el8jbcs
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.17-13.el7jbcs, 1.3.17-13.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-99.el7jbcs, 1.6.1-99.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-20.el7jbcs, 1.15.19-20.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.43.0-11.el7jbcs, 1.43.0-11.el8jbcs
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs
httpd-debugsource - update to 2.4.43-17
mod_ldap - update to 2.4.43-17
httpd-debuginfo - update to 2.4.43-17
mod_proxy_html - update to 2.4.43-17
httpd-tools - update to 2.4.43-17
httpd - update to 2.4.43-17
mod_ssl - update to 2.4.43-17
mod_md - update to 2.4.43-17
mod_session - update to 2.4.43-17
httpd-devel - update to 2.4.43-17
httpd-filesystem - update to 2.4.43-17
httpd-help - update to 2.4.43-17
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-37.el7jbcs, 2.4.51-37.el8jbcs
httpd - update to 2.4.54-3
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-22.el7jbcs, 2.9.3-22.el8jbcs
IBM Aspera Orchestrator - update to 4.0.1.2b9681
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.86.0-2.el7jbcs, 7.86.0-2.el8jbcs
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
PowerScale OneFS - addressed in versions 9.1.0.28, 9.2.1.22, 9.4.0.13, 9.5.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Amazon Linux AMI update for httpd24
- Information disclosure in IBM Rational Build Forge
- QNAS QTS update for Apache HTTP Server
- Multiple Vulnerabilities in QuTS hero Apache HTTP Server component
- Multiple Vulnerabilities in QuTScloud Apache HTTP Server component
- Red Hat JBoss Core Services update for Apache HTTP Server
- Out-of-bounds read in IBM Aspera Orchestrator
- Multiple vulnerabilities in IBM Aspera Faspex
- Multiple vulnerabilities in Dell EMC PowerScale OneFS
- openEuler update for httpd
- Amazon Linux AMI update for httpd
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component