A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer
overflow while processing multipart form uploads. A remote attacker could
send a request causing a process crash which could lead to a denial of
service attack. (CVE-2022-22728)
- https://bugs.mageia.org/show_bug.cgi?id=30778
- https://www.openwall.com/lists/oss-security/2022/08/25/3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2PUUS3JL44UUSLJTSXE46HVKZIW7E7PE/
- https://www.openwall.com/lists/oss-security/2023/01/02/2
- https://lists.debian.org/debian-lts-announce/2023/01/msg00009.html
- https://www.cve.org/CVERecord?id=CVE-2022-22728
- 8/core/libapreq2-2.130.0-31.1.mga8
Get the latest Linux and open source security news straight to your inbox.