CVE-2022-29404

Description

In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
2.32

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.23Windows
Multiple vulnerabilities are fixed in IBM HTTP 9.0.5.13Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Apache HTTP server (USN-5487-1) apache2_2.4.52-1ubuntu4.1_i386.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.52-1ubuntu4.1_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.29-1ubuntu4.24_i386.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.29-1ubuntu4.24_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.41-4ubuntu3.12_i386.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.41-4ubuntu3.12_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.48-3.1ubuntu3.5_i386.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.48-3.1ubuntu3.5_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.52-1ubuntu4.6_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.52-1ubuntu4.6_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.29-1ubuntu4.24_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.29-1ubuntu4.24_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.41-4ubuntu3.14_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.41-4ubuntu3.14_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.48-3.1ubuntu3.5_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.48-3.1ubuntu3.5_amd64.debLinux
Apache HTTP server (USN-5487-3) apache2_2.4.29-1ubuntu4.25_i386.debLinux
Apache HTTP server (USN-5487-3) apache2_2.4.29-1ubuntu4.25_amd64.debLinux
Apache HTTP server (USN-5487-3) apache2-bin_2.4.29-1ubuntu4.27_i386.debLinux
Apache HTTP server (USN-5487-3) apache2-bin_2.4.29-1ubuntu4.27_amd64.debLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-core-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-debugsource-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-devel-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-filesystem-2.4.53-7.el9.noarch.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-manual-2.4.53-7.el9.noarch.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-tools-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_ldap-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_lua-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_proxy_html-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_session-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_ssl-2.4.53-7.el9.x86_64.rpmLinux
SUSE-SU-2022:2342-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) apache2-utils-debuginfo-2.4.51-150200.3.48.1.x86_64.rpmLinux
SUSE-SU-2022:2342-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) apache2-prefork-debuginfo-2.4.51-150200.3.48.1.x86_64.rpmLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.52-1ubuntu4.1_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.52-1ubuntu4.1_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.41-4ubuntu3.12_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.41-4ubuntu3.12_amd64.debLinux
Apache HTTP server (USN-5487-3) apache2-bin_2.4.29-1ubuntu4.25_i386.debLinux
Apache HTTP server (USN-5487-3) apache2-bin_2.4.29-1ubuntu4.25_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234