CVE-2017-12618

Description

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.

Risk Information

Base Score
4.7
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.201

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-11985,CVE-2017-9798,CVE-2017-12618,CVE-2016-8743 are fixed in IBM HTTP 9.0.0.3Windows
Multiple vulnerabilities are fixed in IBM HTTP 7.0.0.45Windows
Vulnerabilities CVE-2017-9798,CVE-2017-12618 are fixed in IBM HTTP 9.0.0.6Windows
Vulnerabilities CVE-2017-9798,CVE-2017-12618 are fixed in IBM HTTP 8.5.5.13Windows
Vulnerabilities CVE-2017-9798,CVE-2017-12618 are fixed in IBM HTTP 8.0.0.15Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.15Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.45Windows
Vulnerabilities CVE-2017-9798,CVE-2017-12618 are fixed in IBM WebSphere 9.0.0.6Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.13Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.2.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple vulnerabilities are fixed in macOS Mojave 10.14.6Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.6 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.5 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.5Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.4Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.4 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.3Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.3 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.2Mac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.1Mac
SUSE-SU-2018:0307-1(SUSE Linux Enterprise Server 11-SP4 ) libapr-util1-1.3.4-12.22.23.3.2.x86_64.rpmLinux
SUSE-SU-2018:0307-1(SUSE Linux Enterprise Server 11-SP4 ) libapr-util1-dbd-sqlite3-1.3.4-12.22.23.3.2.x86_64.rpmLinux
SUSE-SU-2017:3278-1(SUSE Linux Enterprise Server 12-SP2 ) libapr-util1-1.5.3-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:3278-1(SUSE Linux Enterprise Server 12-SP2 ) libapr-util1-dbd-sqlite3-1.5.3-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:3278-1(SUSE Linux Enterprise Server 12-SP2 ) libapr-util1-dbd-sqlite3-debuginfo-1.5.3-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:3278-1(SUSE Linux Enterprise Server 12-SP2 ) libapr-util1-debuginfo-1.5.3-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:3278-1(SUSE Linux Enterprise Server 12-SP2 ) libapr-util1-debugsource-1.5.3-2.3.1.x86_64.rpmLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-602004macOS Mojave 10.14.6
PATCH-602005macOS Mojave 10.14.6 Combo Update
PATCH-602005macOS Mojave 10.14.6 Combo Update
PATCH-602004macOS Mojave 10.14.6
PATCH-602004macOS Mojave 10.14.6
PATCH-602005macOS Mojave 10.14.6 Combo Update
PATCH-602004macOS Mojave 10.14.6
PATCH-602005macOS Mojave 10.14.6 Combo Update
PATCH-602004macOS Mojave 10.14.6
PATCH-602004macOS Mojave 10.14.6

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234