Description
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1162-1 | apr security update |
Debian DLA |
DLA-2897-1 | apr security update |
EUVD |
EUVD-2017-4171 | When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input. |
References
History
No history.
Subscriptions
Apache
Subscribe
Portable Runtime
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Jboss Core Services
Subscribe
Jboss Enterprise Web Server
Subscribe
Rhel Aus
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Rhel Software Collections
Subscribe
Rhel Tus
Subscribe
Software Collections
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T18:43:56.151Z
Reserved: 2017-08-07T00:00:00.000Z
Link: CVE-2017-12613
No data.
Status : Deferred
Published: 2017-10-24T01:29:02.000
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-12613
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD