Stack-based buffer overflow in Apache Portable Runtime - CVE-2022-28331

 

Stack-based buffer overflow in Apache Portable Runtime - CVE-2022-28331

Published: February 2, 2023


Vulnerability identifier: #VU71753
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28331
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the apr_socket_sendv() function. A remote attacker can pass specially crafted input to the application, trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Note, the vulnerability affects Windows installations only.


Affected software

Apache Portable Runtime
IBM Tivoli Monitoring
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Business Automation Manager Open Editions
JBoss Web Server
IBM HTTP Server
Oracle Solaris
PowerScale OneFS

How to mitigate CVE-2022-28331

Install updates from vendor's website.

Apache Portable Runtime - update to 1.7.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
JBoss Web Server - update to 5.7.4
IBM Business Automation Manager Open Editions - update to 9.1.1
IBM HTTP Server - addressed in versions 8.5.5.24, 9.0.5.15
PowerScale OneFS - update to 9.4.0.14

External References

Related Security Bulletins