ALPINE-CVE-2022-25147 PUBLISHED CVSS 6.5 MEDIUM

Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Affected Products

VendorProductVersions
Alpine:v3.14apr-util1.3.9-r3, 1.3.9-r4, 1.3.9-r5
Alpine:v3.22apr-util1.4.1-r1, 1.4.1-r2, 1.5.1-r0
Alpine:v3.20apr1.4.8-r0, 1.4.8-r1, 1.5.0-r0
Alpine:v3.18apr1.6.5-r0, 0, 1.3.3-r0
Alpine:v3.20apr-util1.3.9-r1, 1.3.9-r2, 1.3.9-r3
Alpine:v3.15apr1.7.0-r1, 0, 1.3.3-r0
Alpine:v3.23apr-util1.3.9-r4, 1.6.2-r0, 1.6.1-r9
Alpine:v3.21apr1.3.3-r0, 1.4.6-r0, 1.4.2-r1
Alpine:v3.16apr1.7.0-r2, 1.4.5-r3, 1.4.6-r0
Alpine:v3.21apr-util1.6.2-r0, 1.6.2-r0, 1.6.1-r9
Alpine:v3.22apr1.4.6-r0, 1.4.5-r3, 1.4.5-r2
Alpine:v3.23apr1.5.2-r1, 1.4.2-r2, 1.5.1-r0
Alpine:v3.14apr0, 1.3.3-r0, 1.3.5-r0
Alpine:v3.18apr-util1.6.1-r0, 1.6.1-r1, 1.6.1-r10
Alpine:v3.15apr-util1.3.10-r0, 1.3.11-r0, 1.3.12-r1
Alpine:v3.19apr0, 1.3.5-r0, 1.3.7-r0
Alpine:v3.17apr-util1.3.12-r0, 1.3.9-r1, 1.6.1-r7
Alpine:v3.19apr-util1.3.10-r1, 1.3.10-r0, 0
Alpine:v3.16apr-util1.3.9-r3, 1.3.10-r0, 0
Alpine:v3.17apr1.7.0-r2, 1.7.0-r1, 1.7.0-r0

Timeline

References

Open in Interactive Console →