When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Portable Runtime
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Jboss Core Services
Subscribe
Jboss Enterprise Web Server
Subscribe
Rhel Aus
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Rhel Software Collections
Subscribe
Rhel Tus
Subscribe
Software Collections
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1162-1 | apr security update |
Debian DLA |
DLA-2897-1 | apr security update |
EUVD |
EUVD-2017-4171 | When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T18:43:56.151Z
Reserved: 2017-08-07T00:00:00
Link: CVE-2017-12613
No data.
Status : Deferred
Published: 2017-10-24T01:29:02.000
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-12613
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD