← Back

CVE-2017-12618

nvd nist
Published: Oct 24, 2017Modified: May 13, 2026

JSON object

Loading...
4.7
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.0 / Impact: 3.6
Source: NVD

Description

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.

Affected (59)

1 product
Portable Runtime Utility
Configuration A
59 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 0.9.10
Version 0.9.11
Version 0.9.12
Version 0.9.13
Version 0.9.14
Version 0.9.15
Version 0.9.16
Version 0.9.17
Version 0.9.18
Version 0.9.19
Version 0.9.1
Version 0.9.20
Version 0.9.2
Version 0.9.3
Version 0.9.4
Version 0.9.5
Version 0.9.6
Version 0.9.7
Version 0.9.9
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.2.10
Version 1.2.12
Version 1.2.13
Version 1.2.1
Version 1.2.2
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 1.2.9
Version 1.3.0
Version 1.3.10
Version 1.3.11
Version 1.3.12
Version 1.3.13
Version 1.3.1
Version 1.3.2
Version 1.3.3
Version 1.3.4
Version 1.3.5
Version 1.3.6
Version 1.3.7
Version 1.3.8
Version 1.3.9
Version 1.4.0
Version 1.4.1
Version 1.4.2
Version 1.4.3
Version 1.5.0
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5.4
Version 1.5.5
Version 1.6.0

References (8)

Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.