Описание
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
A flaw was found in Apache Portable Runtime Utility (apr-util). The apr_password_validate() function does not perform constant-time comparisons for hashes or passwords. This vulnerability allows a remote attacker to conduct a timing attack, particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. By observing the time differences in comparisons, an attacker could potentially deduce the content of sensitive information like password hashes.
Отчет
This vulnerability is assessed as Low Impact due to significant practical exploitation barriers. While the theoretical outcome of a successful timing attack is hash disclosure (Confidentiality: High), isolating microsecond-level comparison differences over a network is rendered practically infeasible by unpredictable network latency, packet jitter, and server scheduling noise (Attack Complexity: High). Additionally, RHEL environments natively rely on the system crypt() implementation for standard password checks, bypassing the vulnerable non-constant-time fallback code path in standard deployment scenarios.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | apr-util | Fix deferred | ||
| Red Hat Enterprise Linux 6 | apr-util | Out of support scope | ||
| Red Hat Enterprise Linux 7 | apr-util | Fix deferred | ||
| Red Hat Enterprise Linux 8 | apr-util | Fix deferred | ||
| Red Hat Enterprise Linux 9 | apr-util | Fix deferred | ||
| Red Hat Hardened Images | apr-util | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
APR-util versions 1.6.3 (and earlier) function apr_password_validate() ...
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
EPSS
5.9 Medium
CVSS3