Critical severity9.8NVD Advisory· Published Mar 14, 2022· Updated Jun 17, 2026
CVE-2022-23943
CVE-2022-23943
Description
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
64<=2.4.52+ 2 more
- (no CPE)range: <=2.4.52
- (no CPE)range: 2.4
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: >=2.4.0,<2.4.53
- osv-coords53 versionspkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/apache2&distro=SUSE%20Manager%20Proxy%204.1pkg:bitnami/apachepkg:rpm/almalinux/httpdpkg:rpm/almalinux/mod_http2pkg:rpm/almalinux/mod_proxy_htmlpkg:rpm/almalinux/httpd-corepkg:rpm/suse/apache2&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP2pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/almalinux/httpd-develpkg:rpm/almalinux/httpd-filesystempkg:rpm/almalinux/httpd-manualpkg:rpm/almalinux/httpd-toolspkg:rpm/almalinux/mod_ldappkg:rpm/almalinux/mod_mdpkg:rpm/almalinux/mod_sessionpkg:rpm/almalinux/mod_sslpkg:rpm/almalinux/mod_luapkg:rpm/suse/apache2&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/apache2&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/apache2&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/apache2&distro=openSUSE%20Tumbleweed
< 2.4.23-29.88.1+ 52 more
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.51-35.13.1
- (no CPE)range: < 2.4.51-35.13.1
- (no CPE)range: < 2.4.51-35.13.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.53
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 1.15.7-5.module_el8.6.0+2872+fe0ff7aa
- (no CPE)range: < 1:2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.53-7.el9
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 1:2.0.8-8.module_el8.6.0+2872+fe0ff7aa
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 1:2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.53-7.el9
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.53-1.1
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
11- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2022/03/14/1nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
- lists.debian.org/debian-lts-announce/2022/03/msg00033.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/nvdThird Party Advisory
- security.gentoo.org/glsa/202208-20nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20220321-0001/nvdThird Party Advisory
- www.tenable.com/security/tns-2022-08nvdThird Party Advisory
- www.tenable.com/security/tns-2022-09nvdThird Party Advisory
News mentions
0No linked articles in our index yet.