4.7

CVE-2017-12618

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Portable Runtime Utility Version 0.9.1
Apache ≫ Portable Runtime Utility Version 0.9.2
Apache ≫ Portable Runtime Utility Version 0.9.3
Apache ≫ Portable Runtime Utility Version 0.9.4
Apache ≫ Portable Runtime Utility Version 0.9.5
Apache ≫ Portable Runtime Utility Version 0.9.6
Apache ≫ Portable Runtime Utility Version 0.9.7
Apache ≫ Portable Runtime Utility Version 0.9.9
Apache ≫ Portable Runtime Utility Version 0.9.10
Apache ≫ Portable Runtime Utility Version 0.9.11
Apache ≫ Portable Runtime Utility Version 0.9.12
Apache ≫ Portable Runtime Utility Version 0.9.13
Apache ≫ Portable Runtime Utility Version 0.9.14
Apache ≫ Portable Runtime Utility Version 0.9.15
Apache ≫ Portable Runtime Utility Version 0.9.16
Apache ≫ Portable Runtime Utility Version 0.9.17
Apache ≫ Portable Runtime Utility Version 0.9.18
Apache ≫ Portable Runtime Utility Version 0.9.19
Apache ≫ Portable Runtime Utility Version 0.9.20
Apache ≫ Portable Runtime Utility Version 1.0.0
Apache ≫ Portable Runtime Utility Version 1.0.1
Apache ≫ Portable Runtime Utility Version 1.0.2
Apache ≫ Portable Runtime Utility Version 1.1.0
Apache ≫ Portable Runtime Utility Version 1.1.1
Apache ≫ Portable Runtime Utility Version 1.1.2
Apache ≫ Portable Runtime Utility Version 1.2.1
Apache ≫ Portable Runtime Utility Version 1.2.2
Apache ≫ Portable Runtime Utility Version 1.2.6
Apache ≫ Portable Runtime Utility Version 1.2.7
Apache ≫ Portable Runtime Utility Version 1.2.8
Apache ≫ Portable Runtime Utility Version 1.2.9
Apache ≫ Portable Runtime Utility Version 1.2.10
Apache ≫ Portable Runtime Utility Version 1.2.12
Apache ≫ Portable Runtime Utility Version 1.2.13
Apache ≫ Portable Runtime Utility Version 1.3.0
Apache ≫ Portable Runtime Utility Version 1.3.1
Apache ≫ Portable Runtime Utility Version 1.3.2
Apache ≫ Portable Runtime Utility Version 1.3.3
Apache ≫ Portable Runtime Utility Version 1.3.4
Apache ≫ Portable Runtime Utility Version 1.3.5
Apache ≫ Portable Runtime Utility Version 1.3.6
Apache ≫ Portable Runtime Utility Version 1.3.7
Apache ≫ Portable Runtime Utility Version 1.3.8
Apache ≫ Portable Runtime Utility Version 1.3.9
Apache ≫ Portable Runtime Utility Version 1.3.10
Apache ≫ Portable Runtime Utility Version 1.3.11
Apache ≫ Portable Runtime Utility Version 1.3.12
Apache ≫ Portable Runtime Utility Version 1.3.13
Apache ≫ Portable Runtime Utility Version 1.4.0
Apache ≫ Portable Runtime Utility Version 1.4.1
Apache ≫ Portable Runtime Utility Version 1.4.2
Apache ≫ Portable Runtime Utility Version 1.4.3
Apache ≫ Portable Runtime Utility Version 1.5.0
Apache ≫ Portable Runtime Utility Version 1.5.1
Apache ≫ Portable Runtime Utility Version 1.5.2
Apache ≫ Portable Runtime Utility Version 1.5.3
Apache ≫ Portable Runtime Utility Version 1.5.4
Apache ≫ Portable Runtime Utility Version 1.5.5
Apache ≫ Portable Runtime Utility Version 1.6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.438
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 1 3.6
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:N/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

http://www.securitytracker.com/id/1042004
http://mail-archives.apache.org/mod_mbox/apr-dev/201710.mbox/%3CCACsi252POs4toeJJciwg09_eu2cO3XFg%3DUqsPjXsfjDoeC3-UQ%40mail.gmail.com%3E
Vendor Advisory
Mailing List
http://www.securityfocus.com/bid/101558
Third Party Advisory
VDB Entry
https://lists.debian.org/debian-lts-announce/2017/11/msg00006.html