CVE-2017-12613

Description

When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
0.25

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.2.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple vulnerabilities are fixed in macOS Mojave 10.14.6Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.6 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.5 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.5Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.4Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.4 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.3Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.3 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.2Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.1Mac
Apr security update (CESA-2017:3270) apr-1.3.9-5.el6_9.1.i686.rpmLinux
Apr security update (CESA-2017:3270) apr-1.3.9-5.el6_9.1.x86_64.rpmLinux
Apr security update (CESA-2017:3270) apr-1.4.8-3.el7_4.1.i686.rpmLinux
Apr security update (CESA-2017:3270) apr-1.4.8-3.el7_4.1.x86_64.rpmLinux
Apr security update (CESA-2017:3270) apr-devel-1.3.9-5.el6_9.1.i686.rpmLinux
Apr security update (CESA-2017:3270) apr-devel-1.3.9-5.el6_9.1.x86_64.rpmLinux
Apr security update (CESA-2017:3270) apr-devel-1.4.8-3.el7_4.1.i686.rpmLinux
Apr security update (CESA-2017:3270) apr-devel-1.4.8-3.el7_4.1.x86_64.rpmLinux
(RHSA-2017:3270) Important: apr security update apr-1.3.9-5.el6_9.1.i686.rpmLinux
(RHSA-2017:3270) Important: apr security update apr-1.3.9-5.el6_9.1.x86_64.rpmLinux
(RHSA-2017:3270) Important: apr security update apr-1.4.8-3.el7_4.1.i686.rpmLinux
(RHSA-2017:3270) Important: apr security update apr-1.4.8-3.el7_4.1.x86_64.rpmLinux
(RHSA-2017:3270) Important: apr security update apr-devel-1.3.9-5.el6_9.1.i686.rpmLinux
(RHSA-2017:3270) Important: apr security update apr-devel-1.3.9-5.el6_9.1.x86_64.rpmLinux
(RHSA-2017:3270) Important: apr security update apr-devel-1.4.8-3.el7_4.1.i686.rpmLinux
(RHSA-2017:3270) Important: apr security update apr-devel-1.4.8-3.el7_4.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.3.9-5.el6_4.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.3.9-5.el6_4.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.3.9-5.el6_5.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.3.9-5.el6_5.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.3.9-5.el6_6.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.3.9-5.el6_6.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.3.9-5.el6_7.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.3.9-5.el6_7.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.4.8-3.el7_2.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.4.8-3.el7_2.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.4.8-3.el7_3.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-1.4.8-3.el7_3.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.3.9-5.el6_4.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.3.9-5.el6_4.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.3.9-5.el6_5.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.3.9-5.el6_5.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.3.9-5.el6_6.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.3.9-5.el6_6.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.3.9-5.el6_7.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.3.9-5.el6_7.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.4.8-3.el7_2.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.4.8-3.el7_2.1.x86_64.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.4.8-3.el7_3.1.i686.rpmLinux
(RHSA-2018:1253) Important: apr security update apr-devel-1.4.8-3.el7_3.1.x86_64.rpmLinux
SUSE-SU-2018:1196-1(SUSE Linux Enterprise Server 12-SP3 ) libapr1-1.5.1-4.3.1.x86_64.rpmLinux
SUSE-SU-2018:1196-1(SUSE Linux Enterprise Server 12-SP3 ) libapr1-debuginfo-1.5.1-4.3.1.x86_64.rpmLinux
SUSE-SU-2018:1196-1(SUSE Linux Enterprise Server 12-SP3 ) libapr1-debugsource-1.5.1-4.3.1.x86_64.rpmLinux
SUSE-SU-2018:1322-1(SUSE Linux Enterprise Server 11-SP4 ) libapr1-1.3.3-11.18.19.13.2.x86_64.rpmLinux
Apr update (ELSA-2017-3270) apr-1.3.9-5.el6_9.1.x86_64.rpmLinux
Apr-devel update (ELSA-2017-3270) apr-devel-1.3.9-5.el6_9.1.x86_64.rpmLinux
Apr update (ELSA-2017-3270) apr-1.3.9-5.el6_9.1.i686.rpmLinux
Apr-devel update (ELSA-2017-3270) apr-devel-1.3.9-5.el6_9.1.i686.rpmLinux
Apr update (ELSA-2017-3270) apr-1.4.8-3.el7_4.1.x86_64.rpmLinux
Apr-devel update (ELSA-2017-3270) apr-devel-1.4.8-3.el7_4.1.x86_64.rpmLinux
Apr update (ELSA-2017-3270) apr-1.4.8-3.el7_4.1.i686.rpmLinux
Apr-devel update (ELSA-2017-3270) apr-devel-1.4.8-3.el7_4.1.i686.rpmLinux
(RHSA-2017:3270)Important: security update apr-debuginfo-1.4.8-3.el7_4.1.i686.rpmLinux
(RHSA-2017:3270)Important: security update apr-debuginfo-1.4.8-3.el7_4.1.x86_64.rpmLinux
Out-of-bounds Read Vulnerability (CVE-2017-12613)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-602004macOS Mojave 10.14.6
PATCH-602005macOS Mojave 10.14.6 Combo Update
PATCH-602005macOS Mojave 10.14.6 Combo Update
PATCH-602004macOS Mojave 10.14.6
PATCH-602004macOS Mojave 10.14.6
PATCH-602005macOS Mojave 10.14.6 Combo Update
PATCH-602004macOS Mojave 10.14.6
PATCH-602005macOS Mojave 10.14.6 Combo Update
PATCH-602004macOS Mojave 10.14.6
PATCH-602004macOS Mojave 10.14.6

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234