Critical severity9.8NVD Advisory· Published Jan 31, 2023· Updated Jun 17, 2026
CVE-2022-24963
CVE-2022-24963
Description
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.
Affected products
8cpe:2.3:a:apache:portable_runtime:1.7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apache:portable_runtime:1.7.0:*:*:*:*:*:*:*
- (no CPE)range: =1.7.0
- (no CPE)range: 1.7.0
- osv-coords4 versionspkg:bitnami/aprpkg:rpm/almalinux/aprpkg:rpm/almalinux/apr-develpkg:rpm/opensuse/apr&distro=openSUSE%20Tumbleweed
>= 1.7.0, < 1.7.1+ 3 more
- (no CPE)range: >= 1.7.0, < 1.7.1
- (no CPE)range: < 1.7.0-12.el9_3
- (no CPE)range: < 1.7.0-12.el9_3
- (no CPE)range: < 1.7.2-1.1
Patches
Vulnerability mechanics
References
2- lists.apache.org/thread/fw9p6sdncwsjkstwc066vz57xqzfksq9nvdMailing ListVendor Advisory
- security.netapp.com/advisory/ntap-20230908-0008/nvd
News mentions
0No linked articles in our index yet.