Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12618

Опубликовано: 24 окт. 2017
Источник: debian
EPSS Низкий

Описание

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apr-utilfixed1.6.1-1package
apr-utilno-dsastretchpackage
apr-utilno-dsajessiepackage

Примечания

  • mail-archives.apache.org/mod_mbox/apr-dev/201710.mbox/%3CCACsi252POs4toeJJciwg09_eu2cO3XFg%3DUqsPjXsfjDoeC3-UQ%40mail.gmail.com%3E

  • https://github.com/apache/apr/commit/f672b565c825c34de9ee298b5bdc62c01cdd6147

EPSS

Процентиль: 42%
0.00201
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 8 лет назад

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.

CVSS3: 5.5
redhat
больше 8 лет назад

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.

CVSS3: 4.7
nvd
больше 8 лет назад

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.

suse-cvrf
около 8 лет назад

Security update for libapr-util1

suse-cvrf
около 8 лет назад

Security update for libapr-util1

EPSS

Процентиль: 42%
0.00201
Низкий