CVE-2021-35940
published 2021-08-23CVE-2021-35940: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue…
PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
1.19%
64.4th percentile
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | portable_runtime | — | — |
| debian | apr | < apr 1.7.0-7 (bookworm) | apr 1.7.0-7 (bookworm) |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_oracle7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation FactoryTalk Edge Gateway
cisa_ics·2023-06-13·CVSS 7.1
[HIGH] Rockwell Automation FactoryTalk Edge Gateway
ICS Advisory
##
Rockwell Automation FactoryTalk Edge Gateway
Release DateJune 13, 2023
Alert CodeICSA-23-164-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.1
- ATTENTION: Low attack complexity
- Vendor: Rockwell Automation
- Equipment: FactoryTalk Edge Gateway
- Vulnerability: Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow a local user to cause the program to crash, causing a denial of service.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Rockwell Automation reports this vulnerability affects the following FactoryTalk Edge Gateway products:
- FactoryTalk Edge Gateway: v1.3
## 3.2 VULNERABILITY OVERVIEW
3.2.1 OUT-OF-BOUNDS READ CWE-125
An out of bounds array read vulnerability was fixed in the apr_time_e
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache Portable Runtime) — CVE-2021-35940
vendor_oracle·2022-07-15·CVSS 7.1
CVE-2021-35940 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache Portable Runtime) — CVE-2021-35940
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache Portable Runtime) vulnerability
CVE: CVE-2021-35940
CVSS: 7.1
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2022 (JUL 2022)
Ubuntu
APR vulnerability
vendor_ubuntu·2021-08-30
CVE-2021-35940 APR vulnerability
Title: APR vulnerability
Summary: APR could be made to expose sensitive information if it received a specially crafted input.
It was discovered that APR incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
apr: Regression of CVE-2017-12613 fix in apr 1.7
vendor_redhat·2021-08-23·CVSS 7.1
CVE-2021-35940 [HIGH] CWE-125 apr: Regression of CVE-2017-12613 fix in apr 1.7
apr: Regression of CVE-2017-12613 fix in apr 1.7
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
Package: apr (Red Hat Enterprise Linux 6) - Not affected
Package: apr (Red Hat Enterprise Linux 7) - Not affected
Package: apr (Red Hat Enterprise Linux 8) - Not affected
Package: apr (Red Hat Enterprise Linux 9) - Not affected
Package: jbcs-httpd24-apr (Red Hat JBoss Core Services) - Not affected
Package: apr (Red Hat JBoss Web Server 3) - Not affected
Package: apr (Red Hat JBoss Web Server 5) - Not affected
Debian
CVE-2021-35940: apr - An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Ap...
vendor_debian·2021·CVSS 7.1
CVE-2021-35940 [HIGH] CVE-2021-35940: apr - An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Ap...
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
Scope: local
bookworm: resolved (fixed in 1.7.0-7)
bullseye: resolved (fixed in 1.7.0-6+deb11u1)
forky: resolved (fixed in 1.7.0-7)
sid: resolved (fixed in 1.7.0-7)
trixie: resolved (fixed in 1.7.0-7)
GHSA
GHSA-95qq-4mqm-pp5g: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1
ghsa_unreviewed·2022-05-24·CVSS 7.1
CVE-2021-35940 [HIGH] CWE-125 GHSA-95qq-4mqm-pp5g: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
OSV
CVE-2021-35940: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1
osv·2021-08-23·CVSS 7.1
CVE-2021-35940 [HIGH] CVE-2021-35940: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://mail-archives.apache.org/mod_mbox/www-announce/201710.mbox/%3CCACsi251B8UaLvM-rrH9fv57-zWi0zhyF3275_jPg1a9VEVVoxw%40mail.gmail.com%3Ehttp://svn.apache.org/viewvc?view=revision&revision=1891198http://www.openwall.com/lists/oss-security/2021/08/23/1https://dist.apache.org/repos/dist/release/apr/patches/apr-1.7.0-CVE-2021-35940.patchhttps://lists.apache.org/thread.html/r1c788464a25fbc046a72aff451bc8186386315d92a2dd0349903fa4f%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r317c398ee5736e627f7887b06607e5c58b45a696d352ba8c14615f55%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/r54c755c74b9e3846cfd84039b1967d37d2870750a02d7c603983f6ed%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r72479f4dcffaa8a4732d5a0e87fecc4bace4932e28fc26f7d400e2b3%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r72a069753b9363c29732e59ad8f0d22a633fb6a699980407511ac961%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/r7bb4a6ed88fc48152174e664aae30ea9a8b058eb5b44cf08cb9beb4b%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/r7bb4a6ed88fc48152174e664aae30ea9a8b058eb5b44cf08cb9beb4b%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/ra38094406cc38a05218ebd1158187feda021b0c3a1df400bbf296af8%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/rafe54755850e93de287c36540972457b2dd86332106aa7817c7c27fb%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb1f3c85f50fbd924a0051675118d1609e57957a02ece7facb723155b%40%3Cannounce.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujul2022.htmlhttp://mail-archives.apache.org/mod_mbox/www-announce/201710.mbox/%3CCACsi251B8UaLvM-rrH9fv57-zWi0zhyF3275_jPg1a9VEVVoxw%40mail.gmail.com%3Ehttp://svn.apache.org/viewvc?view=revision&revision=1891198http://www.openwall.com/lists/oss-security/2021/08/23/1https://dist.apache.org/repos/dist/release/apr/patches/apr-1.7.0-CVE-2021-35940.patchhttps://lists.apache.org/thread.html/r1c788464a25fbc046a72aff451bc8186386315d92a2dd0349903fa4f%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r317c398ee5736e627f7887b06607e5c58b45a696d352ba8c14615f55%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/r54c755c74b9e3846cfd84039b1967d37d2870750a02d7c603983f6ed%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r72479f4dcffaa8a4732d5a0e87fecc4bace4932e28fc26f7d400e2b3%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r72a069753b9363c29732e59ad8f0d22a633fb6a699980407511ac961%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/r7bb4a6ed88fc48152174e664aae30ea9a8b058eb5b44cf08cb9beb4b%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/r7bb4a6ed88fc48152174e664aae30ea9a8b058eb5b44cf08cb9beb4b%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/ra38094406cc38a05218ebd1158187feda021b0c3a1df400bbf296af8%40%3Cdev.apr.apache.org%3Ehttps://lists.apache.org/thread.html/rafe54755850e93de287c36540972457b2dd86332106aa7817c7c27fb%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb1f3c85f50fbd924a0051675118d1609e57957a02ece7facb723155b%40%3Cannounce.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujul2022.html
2021-08-23
Published