CVE-2023-49582
published 2024-08-26CVE-2023-49582: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.33%
25.2th percentile
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data.
This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h)
Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | portable_runtime | >= 0.9.0 < 1.7.5 | 1.7.5 |
| apache_software_foundation | apache_portable_runtime | 0.9.0 – 1.7.4 | — |
| debian | apr | < apr 1.7.2-3+deb12u1 (bookworm) | apr 1.7.2-3+deb12u1 (bookworm) |
| msrc | azl3_apr_1.7.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_apr_1.7.5-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_apr_1.7.2-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_apr_1.7.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Apache Portable Runtime) — CVE-2023-49582
vendor_oracle·2025-07-15·CVSS 5.5
CVE-2023-49582 [MEDIUM] Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Apache Portable Runtime) — CVE-2023-49582
Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Apache Portable Runtime) vulnerability
CVE: CVE-2023-49582
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Portable Runtime) — CVE-2023-49582
vendor_oracle·2025-04-15·CVSS 5.5
CVE-2023-49582 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Apache Portable Runtime) — CVE-2023-49582
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Portable Runtime) vulnerability
CVE: CVE-2023-49582
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache Portable Runtime) — CVE-2023-49582
vendor_oracle·2025-01-15·CVSS 5.5
CVE-2023-49582 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache Portable Runtime) — CVE-2023-49582
Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache Portable Runtime) vulnerability
CVE: CVE-2023-49582
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2025 (JAN 2025)
Ubuntu
APR vulnerability
vendor_ubuntu·2024-10-16
CVE-2023-49582 APR vulnerability
Title: APR vulnerability
Summary: The system could be made to expose sensitive information.
USN-7038-1 fixed a vulnerability in Apache Portable Runtime (APR) library.
This update provides the corresponding update for Ubuntu 14.04 LTS.
Original advisory details:
Thomas Stangner discovered a permission vulnerability in the Apache
Portable Runtime (APR) library. A local attacker could possibly use this
issue to read named shared memory segments, potentially exposing sensitive
application data.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
APR vulnerability
vendor_ubuntu·2024-09-26
CVE-2023-49582 APR vulnerability
Title: APR vulnerability
Summary: The system could be made to expose sensitive information.
Thomas Stangner discovered a permission vulnerability in the Apache
Portable Runtime (APR) library. A local attacker could possibly use this
issue to read named shared memory segments, potentially exposing sensitive
application data.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
APR: Lax permissions in Apache Portable Runtime shared memory
vendor_redhat·2024-08-26·CVSS 5.5
CVE-2023-49582 [MEDIUM] CWE-732 APR: Lax permissions in Apache Portable Runtime shared memory
APR: Lax permissions in Apache Portable Runtime shared memory
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data.
This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h)
Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.
A flaw was found in the Apache Portable Runtime (APR) library. This issue allows local users to read named shared memory segments due to incorrect permissions, potentially revealing sensitive application data.
Statement: This issue does not affect non-Unix platforms or builds with APR_USE_SHMEM_SHMGET=1, which use the method based on SysV IPC shmget function (rathe
Microsoft
Apache Portable Runtime (APR): Unexpected lax shared memory permissions
vendor_msrc·2024-08-13·CVSS 5.5
CVE-2023-49582 [MEDIUM] CWE-732 Apache Portable Runtime (APR): Unexpected lax shared memory permissions
Apache Portable Runtime (APR): Unexpected lax shared memory permissions
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refere
Debian
CVE-2023-49582: apr - Lax permissions set by the Apache Portable Runtime library on Unix platforms wou...
vendor_debian·2023·CVSS 5.5
CVE-2023-49582 [MEDIUM] CVE-2023-49582: apr - Lax permissions set by the Apache Portable Runtime library on Unix platforms wou...
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.
Scope: local
bookworm: resolved (fixed in 1.7.2-3+deb12u1)
bullseye: open
forky: resolved (fixed in 1.7.5-1)
sid: resolved (fixed in 1.7.5-1)
trixie: resolved (fixed in 1.7.5-1)
GHSA
GHSA-j26h-qjc9-68hh: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pote
ghsa_unreviewed·2024-08-26
CVE-2023-49582 [MEDIUM] CWE-732 GHSA-j26h-qjc9-68hh: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pote
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data.
This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h)
Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.
OSV
CVE-2023-49582: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pote
osv·2024-08-26·CVSS 5.5
CVE-2023-49582 [MEDIUM] CVE-2023-49582: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pote
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data.
This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h)
Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.
OSV
CVE-2023-49582: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pote
osv·2024-08-26·CVSS 5.5
CVE-2023-49582 [MEDIUM] CVE-2023-49582: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pote
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.
No detection rules found.
No public exploits indexed.
2024-08-26
Published