Integer overflow in Apache APR-util - CVE-2022-25147

 

Integer overflow in Apache APR-util - CVE-2022-25147

Published: February 2, 2023


Vulnerability identifier: #VU71754
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25147
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the apr_base64() function. A remote attacker can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Apache APR-util
Amazon Linux AMI
Debian Linux
F5OS
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
CentOS
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Ubuntu
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
IBM Tivoli Monitoring
OpenShift Logging
Dell Secure Connect Gateway
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Oracle Financial Services Behavior Detection Platform
Oracle Communications Diameter Signaling Router
Oracle HTTP Server
IBM MQ Operator
Isolation Segment
IBM Security Verify Governance
BIG-IP
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Traffix SDC
JBoss Core Services
EMC ECS
IBM Engineering Requirements Management DOORS Next
cflinuxfs3
IBM supplied MQ Advanced container images
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libaprutil1 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
apr-util-openssl
apr-util-odbc
apr-util-nss
apr-util-mysql
apr-util-ldap
apr-util-devel
apr-util-pgsql
apr-util-sqlite
apr-util
apr-util (Red Hat package)
libapr-util1-debugsource
libapr-util1-debuginfo
libapr-util1
libapr-util1-dbd-sqlite3
libapr-util1-dbd-sqlite3-debuginfo
libapr-util1-devel
apr-util (Debian package)
apr-util-bdb
apr-util-debugsource
apr-util-debuginfo
jbcs-httpd24-apr-util (Red Hat package)
libapr-util1-dbd-pgsql
libapr-util1-dbd-pgsql-debuginfo
libapr-util1-dbd-mysql-debuginfo
libapr-util1-dbd-mysql
libapr-util1-dbm-db-debuginfo
libapr-util1-dbm-db
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
IBM HTTP Server

How to mitigate CVE-2022-25147

Install updates from vendor's website.

Apache APR-util - update to 1.6.2
BIG-IP - update to 17.5.1.1
F5OS - addressed in versions 1.5.0, 1.6.0
Migration Toolkit for Containers - update to 1.7.10
JBoss Core Services - update to 2.4.51 SP2
EMC ECS - update to 3.7.0.6
Red Hat OpenShift Container Platform - addressed in versions 4.11.42, 4.12.19, 4.13.1, 4.13.2
OpenShift Logging - update to 5.7.2
Dell Secure Connect Gateway - update to 5.16
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
libaprutil1 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.6.1-2ubuntu0.1, 1.6.1-4ubuntu2.1, 1.6.1-5ubuntu4.22.04.1, 1.6.1-5ubuntu4.22.10.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-33.el7jbcs, 0.4.10-33.el8jbcs
cflinuxfs3 - update to 0.352.0
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-18.el7jbcs, 1.0.0-18.el8jbcs
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.18-2.el7jbcs, 1.3.18-2.el8jbcs
apr-util-openssl - addressed in versions 1.5.2-6, 1.6.1-6.0.1
apr-util-odbc - addressed in versions 1.5.2-6, 1.6.1-6.0.1
apr-util-nss - update to 1.5.2-6
apr-util-mysql - addressed in versions 1.5.2-6, 1.6.1-6.0.1
apr-util-ldap - addressed in versions 1.5.2-6, 1.6.1-6.0.1
apr-util-devel - addressed in versions 1.5.2-6, 1.6.1-6.0.1
apr-util-pgsql - addressed in versions 1.5.2-6, 1.6.1-6.0.1
apr-util-sqlite - addressed in versions 1.5.2-6, 1.6.1-6.0.1
apr-util - addressed in versions 1.5.2-6, 1.6.1-6.0.1
apr-util (Red Hat package) - addressed in versions 1.5.2-6.el7_9.1, 1.6.1-6.el8_1.1, 1.6.1-6.el8_2.1, 1.6.1-6.el8_4.1, 1.6.1-6.el8_6.1, 1.6.1-6.el8_8.1, 1.6.1-20.el9_0.1, 1.6.1-20.el9_2.1
libapr-util1-debugsource - addressed in versions 1.5.3-2.11.1, 1.5.3-8.7.1
libapr-util1-debuginfo - addressed in versions 1.5.3-2.11.1, 1.5.3-8.7.1, 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
libapr-util1 - addressed in versions 1.5.3-2.11.1, 1.5.3-8.7.1, 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
libapr-util1-dbd-sqlite3 - addressed in versions 1.5.3-2.11.1, 1.5.3-8.7.1, 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
libapr-util1-dbd-sqlite3-debuginfo - addressed in versions 1.5.3-2.11.1, 1.5.3-8.7.1, 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
libapr-util1-devel - update to 1.5.3-8.7.1
apr-util - addressed in versions 1.5.4-6.19, 1.6.3-1
apr-util (Debian package) - update to 1.6.1-5+deb11u1
apr-util-bdb - update to 1.6.1-6.0.1
apr-util-pgsql - update to 1.6.1-14
apr-util-debugsource - update to 1.6.1-14
apr-util-debuginfo - update to 1.6.1-14
apr-util-odbc - update to 1.6.1-14
apr-util - update to 1.6.1-14
apr-util-devel - update to 1.6.1-14
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-101.el7jbcs, 1.6.1-101.el8jbcs
libapr-util1-dbd-pgsql - addressed in versions 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
libapr-util1-dbd-pgsql-debuginfo - addressed in versions 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
libapr-util1-dbd-mysql-debuginfo - addressed in versions 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
libapr-util1-dbd-mysql - addressed in versions 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
apr-util-devel - addressed in versions 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
apr-util-debugsource - addressed in versions 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
apr-util-debuginfo - addressed in versions 1.6.1-150000.4.9.1, 1.6.1-150200.12.3.1, 1.6.1-150300.18.5.1
libapr-util1-dbm-db-debuginfo - update to 1.6.1-150300.18.5.1
libapr-util1-dbm-db - update to 1.6.1-150300.18.5.1
apr-util - update to 1.6.3
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-23.el7jbcs, 1.15.19-23.el8jbcs
IBM MQ Operator - addressed in versions 2.0.11, 2.3.3
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-20.el7jbcs, 2.4.0-20.el8jbcs
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-39.el7jbcs, 2.4.51-39.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-24.el7jbcs, 2.9.3-24.el8jbcs
Isolation Segment - addressed in versions 2.11.29, 2.12.19, 2.13.14, 3.0.7, 4.0.0
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.0.1-1.el7jbcs, 8.0.1-1.el8jbcs
IBM HTTP Server - addressed in versions 8.5.5.24, 9.0.5.15
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.5-r2, 9.3.2.1-r2
IBM Security Verify Governance - update to 10.0.2.0.1

External References

Related Security Bulletins