CVE-2017-12618
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
24/10/2017
Last modified:
20/04/2025
Description
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
Impact
Base Score 3.x
4.70
Severity 3.x
MEDIUM
Base Score 2.0
1.90
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:portable_runtime_utility:0.9.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.13:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.14:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.15:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:portable_runtime_utility:0.9.16:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://mail-archives.apache.org/mod_mbox/apr-dev/201710.mbox/%3CCACsi252POs4toeJJciwg09_eu2cO3XFg%3DUqsPjXsfjDoeC3-UQ%40mail.gmail.com%3E
- http://www.securityfocus.com/bid/101558
- http://www.securitytracker.com/id/1042004
- https://lists.debian.org/debian-lts-announce/2017/11/msg00006.html
- http://mail-archives.apache.org/mod_mbox/apr-dev/201710.mbox/%3CCACsi252POs4toeJJciwg09_eu2cO3XFg%3DUqsPjXsfjDoeC3-UQ%40mail.gmail.com%3E
- http://www.securityfocus.com/bid/101558
- http://www.securitytracker.com/id/1042004
- https://lists.debian.org/debian-lts-announce/2017/11/msg00006.html



