Back

CRITICAL

mod_sed: Read/write beyond bounds

Published Mar 14, 2022

Description

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

Affected products

Remediation

Red Hat statement

The `mod_sed` module is disabled by default on Red Hat Enterprise Linux 7 and 8. For this reason, the flaw has been rated as having a security impact of Moderate. The httpd package as shipped with Red Hat Enterprise Linux 6 is not affected by this flaw because the `mod_sed` module is available only in httpd 2.3 and later.

Red Hat mitigation

Disabling mod_sed and restarting httpd will mitigate this flaw. See https://access.redhat.com/articles/10649 for more information.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Mar 14, 2022
Updated Aug 3, 2024
Reserved Jan 25, 2022
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 14, 2022