PT-2017-4213 · Apache+4 · Apache Portable Runtime+4
CVE-2017-12613
·
Publicado
2017-10-24
·
Atualizado
2024-11-07
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Portable Runtime APR versions 1.6.2 and prior
Description
The issue is related to the
apr time exp*() and apr os exp time*() functions in the Apache Portable Runtime APR. When these functions are invoked with an invalid month field value, out of bounds memory may be accessed, potentially revealing the contents of a different static heap value or resulting in program termination. This may represent an information disclosure or denial of service vulnerability to applications that call these APR functions with unvalidated external input.Recommendations
For Apache Portable Runtime APR versions 1.6.2 and prior, consider updating to a newer version to mitigate the risk.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Apache Portable Runtime
Centos
Red Hat
Suse