Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-49582

Опубликовано: 26 авг. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.

A flaw was found in the Apache Portable Runtime (APR) library. This issue allows local users to read named shared memory segments due to incorrect permissions, potentially revealing sensitive application data.

Отчет

This issue does not affect non-Unix platforms or builds with APR_USE_SHMEM_SHMGET=1, which use the method based on SysV IPC shmget function (rather than builds with APR_USE_SHMEM_MMAP_SHM=1, which use the method based on POSIX shm_open function). The APR library as shipped in Red Hat Enterprise Linux 6, 7, 8, 9 and in Red Hat JBoss Core Services is not affected by this issue because they use the method based on SysV IPC shmget function as explained above.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10aprAffected
Red Hat Enterprise Linux 10apr-utilNot affected
Red Hat Enterprise Linux 6aprNot affected
Red Hat Enterprise Linux 7aprNot affected
Red Hat Enterprise Linux 8aprNot affected
Red Hat Enterprise Linux 9aprNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-aprNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=2307913APR: Lax permissions in Apache Portable Runtime shared memory

EPSS

Процентиль: 11%
0.00038
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
10 месяцев назад

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.

CVSS3: 5.5
nvd
10 месяцев назад

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.

CVSS3: 5.5
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 5.5
debian
10 месяцев назад

Lax permissions set by the Apache Portable Runtime library on Unix pla ...

suse-cvrf
9 месяцев назад

Security update for apr

EPSS

Процентиль: 11%
0.00038
Низкий

5.5 Medium

CVSS3