CVE-2017-12613
published 2017-10-24CVE-2017-12613: When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
1.75%
75.4th percentile
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | portable_runtime | < 1.7.0 | 1.7.0 |
| apache | portable_runtime | — | — |
| apache_software_foundation | apache_portable_runtime | — | — |
| apple | macos_mojave | — | — |
| apple | macos_mojave_10.14.1_security_update_2018-002_high_sierra_security_update_2018-0 | — | — |
| debian | apr | < apr 1.6.3-1 (bookworm) | apr 1.6.3-1 (bookworm) |
| debian | apr | < apr 1.7.0-7 (bookworm) | apr 1.7.0-7 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| msrc | cm1_apr_1.6.3-1_on_cbl_mariner_1.0 | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-95qq-4mqm-pp5g: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1
ghsa_unreviewed·2022-05-24·CVSS 7.1
CVE-2021-35940 [HIGH] CWE-125 GHSA-95qq-4mqm-pp5g: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
GHSA
GHSA-v99m-xvmc-cgf3: When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1
ghsa_unreviewed·2022-05-13
CVE-2017-12613 [HIGH] CWE-125 GHSA-v99m-xvmc-cgf3: When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
OSV
CVE-2021-35940: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1
osv·2021-08-23·CVSS 7.1
CVE-2021-35940 [HIGH] CVE-2021-35940: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
OSV
CVE-2017-12613: When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1
osv·2017-10-24·CVSS 7.1
CVE-2017-12613 [HIGH] CVE-2017-12613: When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
CISA ICS
Rockwell Automation FactoryTalk Edge Gateway
cisa_ics·2023-06-13·CVSS 7.1
[HIGH] Rockwell Automation FactoryTalk Edge Gateway
ICS Advisory
##
Rockwell Automation FactoryTalk Edge Gateway
Release DateJune 13, 2023
Alert CodeICSA-23-164-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.1
- ATTENTION: Low attack complexity
- Vendor: Rockwell Automation
- Equipment: FactoryTalk Edge Gateway
- Vulnerability: Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow a local user to cause the program to crash, causing a denial of service.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Rockwell Automation reports this vulnerability affects the following FactoryTalk Edge Gateway products:
- FactoryTalk Edge Gateway: v1.3
## 3.2 VULNERABILITY OVERVIEW
3.2.1 OUT-OF-BOUNDS READ CWE-125
An out of bounds array read vulnerability was fixed in the apr_time_e
Red Hat
apr: Regression of CVE-2017-12613 fix in apr 1.7
vendor_redhat·2021-08-23·CVSS 7.1
CVE-2021-35940 [HIGH] CWE-125 apr: Regression of CVE-2017-12613 fix in apr 1.7
apr: Regression of CVE-2017-12613 fix in apr 1.7
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
Package: apr (Red Hat Enterprise Linux 6) - Not affected
Package: apr (Red Hat Enterprise Linux 7) - Not affected
Package: apr (Red Hat Enterprise Linux 8) - Not affected
Package: apr (Red Hat Enterprise Linux 9) - Not affected
Package: jbcs-httpd24-apr (Red Hat JBoss Core Services) - Not affected
Package: apr (Red Hat JBoss Web Server 3) - Not affected
Package: apr (Red Hat JBoss Web Server 5) - Not affected
Debian
CVE-2021-35940: apr - An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Ap...
vendor_debian·2021·CVSS 7.1
CVE-2021-35940 [HIGH] CVE-2021-35940: apr - An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Ap...
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
Scope: local
bookworm: resolved (fixed in 1.7.0-7)
bullseye: resolved (fixed in 1.7.0-6+deb11u1)
forky: resolved (fixed in 1.7.0-7)
sid: resolved (fixed in 1.7.0-7)
trixie: resolved (fixed in 1.7.0-7)
Apple
CVE-2017-12613: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
vendor_apple·2018-10-30·CVSS 7.1
CVE-2017-12613 [HIGH] CVE-2017-12613: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
Product: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
CVE: CVE-2017-12613
Component: APR
Impact: Multiple buffer overflow issues existed in Perl
Description: Multiple issues in Perl were addressed with improved memory handling.
Apple
CVE-2017-12613: macOS Mojave 10.14
vendor_apple·2018-09-24·CVSS 7.1
CVE-2017-12613 [HIGH] CVE-2017-12613: macOS Mojave 10.14
Apple Security Update: About the security content of macOS Mojave 10.14
Product: macOS Mojave
Version: 10.14
CVE: CVE-2017-12613
Component: APR
Impact: Multiple buffer overflow issues existed in Perl
Description: Multiple issues in Perl were addressed with improved memory handling.
Red Hat
apr: Out-of-bounds array deref in apr_time_exp*() functions
vendor_redhat·2017-10-23·CVSS 7.1
CVE-2017-12613 [HIGH] CWE-125 apr: Out-of-bounds array deref in apr_time_exp*() functions
apr: Out-of-bounds array deref in apr_time_exp*() functions
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
An out-of-bounds array dereference was found in apr_time_exp_get(). An attacker could abuse an unvalidated usage of this function to cause a denial of service or potentially lead to data leak.
Package: apr (Red Hat Enterprise Linux 5) -
Microsoft
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting th
vendor_msrc·2017-10-10·CVSS 7.1
CVE-2017-12613 [HIGH] CWE-125 When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting th
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and mos
Debian
CVE-2017-12613: apr - When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid...
vendor_debian·2017·CVSS 7.1
CVE-2017-12613 [HIGH] CVE-2017-12613: apr - When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid...
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
Scope: local
bookworm: resolved (fixed in 1.6.3-1)
bullseye: resolved (fixed in 1.6.3-1)
forky: resolved (fixed in 1.6.3-1)
sid: resolved (fixed in 1.6.3-1)
trixie: resolved (fixed in 1.6.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12613 apr: Out-of-bounds array deref in apr_time_exp*() functions [fedora-all]
bugzilla·2017-10-26·CVSS 7.1
CVE-2017-12613 [HIGH] CVE-2017-12613 apr: Out-of-bounds array deref in apr_time_exp*() functions [fedora-all]
CVE-2017-12613 apr: Out-of-bounds array deref in apr_time_exp*() functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2017-12613 apr: Out-of-bounds array deref in apr_time_exp*() functions
bugzilla·2017-10-26·CVSS 7.1
CVE-2017-12613 [HIGH] CVE-2017-12613 apr: Out-of-bounds array deref in apr_time_exp*() functions
CVE-2017-12613 apr: Out-of-bounds array deref in apr_time_exp*() functions
When apr_exp_time*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
External References:
http://www.apache.org/dist/apr/Announcement1.x.html
Discussion:
Created apr tracking bugs for this issue:
Affects: fedora-all [bug 1506524]
---
Upstream fix: https://svn.apache.org/viewvc?view=re
http://www.apache.org/dist/apr/Announcement1.x.htmlhttp://www.openwall.com/lists/oss-security/2021/08/23/1http://www.securityfocus.com/bid/101560http://www.securitytracker.com/id/1042004https://access.redhat.com/errata/RHSA-2017:3270https://access.redhat.com/errata/RHSA-2017:3475https://access.redhat.com/errata/RHSA-2017:3476https://access.redhat.com/errata/RHSA-2017:3477https://access.redhat.com/errata/RHSA-2018:0316https://access.redhat.com/errata/RHSA-2018:0465https://access.redhat.com/errata/RHSA-2018:0466https://access.redhat.com/errata/RHSA-2018:1253https://lists.apache.org/thread.html/12489f2e4a9f9d390235c16298aca0d20658789de80d553513977f13%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r270dd5022db194b78acaf509216a33c85f3da43757defa05cc766339%40%3Ccommits.apr.apache.org%3Ehttps://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/ra38094406cc38a05218ebd1158187feda021b0c3a1df400bbf296af8%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/rb1f3c85f50fbd924a0051675118d1609e57957a02ece7facb723155b%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rcc48a0acebbd74bbdeebc02ff228bb72c0631b21823fffe27d4691e9%40%3Ccommits.apr.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2017/11/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2022/01/msg00023.htmlhttps://svn.apache.org/viewvc?view=revision&revision=1807976http://www.apache.org/dist/apr/Announcement1.x.htmlhttp://www.openwall.com/lists/oss-security/2021/08/23/1http://www.securityfocus.com/bid/101560http://www.securitytracker.com/id/1042004https://access.redhat.com/errata/RHSA-2017:3270https://access.redhat.com/errata/RHSA-2017:3475https://access.redhat.com/errata/RHSA-2017:3476https://access.redhat.com/errata/RHSA-2017:3477https://access.redhat.com/errata/RHSA-2018:0316https://access.redhat.com/errata/RHSA-2018:0465https://access.redhat.com/errata/RHSA-2018:0466https://access.redhat.com/errata/RHSA-2018:1253https://lists.apache.org/thread.html/12489f2e4a9f9d390235c16298aca0d20658789de80d553513977f13%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r270dd5022db194b78acaf509216a33c85f3da43757defa05cc766339%40%3Ccommits.apr.apache.org%3Ehttps://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/ra38094406cc38a05218ebd1158187feda021b0c3a1df400bbf296af8%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/rb1f3c85f50fbd924a0051675118d1609e57957a02ece7facb723155b%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rcc48a0acebbd74bbdeebc02ff228bb72c0631b21823fffe27d4691e9%40%3Ccommits.apr.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2017/11/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2022/01/msg00023.htmlhttps://svn.apache.org/viewvc?view=revision&revision=1807976
2017-10-24
Published