CVE-2021-35940
Description
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
Risk Information
Base Score
7.1
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
0.057
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities are affected in Oracle HTTP Server 12.2.1.3.0 | Windows |
| Multiple vulnerabilities are affected in Oracle HTTP Server 12.2.1.4.0 | Windows |
| Apache Portable Runtime Library (USN-5056-1) libapr1_1.7.0-6ubuntu0.1_i386.deb | Linux |
| Apache Portable Runtime Library (USN-5056-1) libapr1_1.7.0-6ubuntu0.1_amd64.deb | Linux |
| apr Security Update (ALAS-2023-016) apr-1.7.2-2.amzn2023.0.2.x86_64.rpm | Linux |
| apr Security Update (ALAS-2023-016) apr-devel-1.7.2-2.amzn2023.0.2.x86_64.rpm | Linux |
| apr Security Update (ALAS-2023-1936) apr-1.7.2-1.amzn2.i686.rpm | Linux |
| apr Security Update (ALAS-2023-1936) apr-1.7.2-1.amzn2.x86_64.rpm | Linux |
| apr Security Update (ALAS-2023-1936) apr-devel-1.7.2-1.amzn2.x86_64.rpm | Linux |
| apr Security Update (ALAS2023-2023-016) apr-1.7.2-2.amzn2023.0.2.x86_64.rpm | Linux |
| apr Security Update (ALAS2023-2023-016) apr-devel-1.7.2-2.amzn2023.0.2.x86_64.rpm | Linux |
| Out-of-bounds Read Vulnerability (CVE-2021-35940) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234