CVE-2021-35940

Description

An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
0.057

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle HTTP Server 12.2.1.3.0Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 12.2.1.4.0Windows
Apache Portable Runtime Library (USN-5056-1) libapr1_1.7.0-6ubuntu0.1_i386.debLinux
Apache Portable Runtime Library (USN-5056-1) libapr1_1.7.0-6ubuntu0.1_amd64.debLinux
apr Security Update (ALAS-2023-016) apr-1.7.2-2.amzn2023.0.2.x86_64.rpmLinux
apr Security Update (ALAS-2023-016) apr-devel-1.7.2-2.amzn2023.0.2.x86_64.rpmLinux
apr Security Update (ALAS-2023-1936) apr-1.7.2-1.amzn2.i686.rpmLinux
apr Security Update (ALAS-2023-1936) apr-1.7.2-1.amzn2.x86_64.rpmLinux
apr Security Update (ALAS-2023-1936) apr-devel-1.7.2-1.amzn2.x86_64.rpmLinux
apr Security Update (ALAS2023-2023-016) apr-1.7.2-2.amzn2023.0.2.x86_64.rpmLinux
apr Security Update (ALAS2023-2023-016) apr-devel-1.7.2-2.amzn2023.0.2.x86_64.rpmLinux
Out-of-bounds Read Vulnerability (CVE-2021-35940)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234