CVE-2022-28331

CVE-2022-28331: Apache Portable Runtime (APR): Windows out-of-bounds write in apr_socket_sendv function

Vendor Apache Software Foundation
Product Apache Portable Runtime (APR)
Weakness CWE-190
Published January 31, 2023
Last update March 27, 2025

CVSS base score

What the vulnerability does

Description

On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.

Key dates

Disclosure timeline

January 31, 2023 CVE published
March 27, 2025 Record updated