Impact
A heap-based buffer overflow was discovered in the APR redis client, a component of the Apache Portable Runtime Utility. The flaw can corrupt heap memory and could lead to arbitrary code execution or a denial of service. This vulnerability falls under CWE‑120 and CWE‑122, indicating a heap-based buffer overflow that permits out‑of‑bounds writes and can be exploited with untrusted data reaching the client.
Affected Systems
Apache Portable Runtime Utility, versions 1.6.0 through 1.6.3, are affected. Systems that incorporate any of these releases of the APR redis client should examine whether the client is actively used and determine if an upgrade is required.
Risk and Exploitability
A CVSS score of 7.5 indicates high severity, an EPSS score of 0.00528 (0.528%) indicates a very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. While the precise likelihood of exploitation is uncertain, the described heap corruption could be triggered by malformed input delivered to the redis client. Based on the description, it is inferred that the client can be accessed from external contexts, suggesting a potential remote attack vector, although local privilege escalation or other conditions may also be possible.
OpenCVE Enrichment
Debian DLA
Debian DSA