An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
2021-08-23T10:15:07.230
2024-11-21T06:12:47.590
Modified
CVSSv3.1: 7.1 (HIGH)
AV:L/AC:L/Au:N/C:P/I:N/A:P
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | portable_runtime | 1.7.0 | Yes |
Application | oracle | http_server | 12.2.1.3.0 | Yes |
Application | oracle | http_server | 12.2.1.4.0 | Yes |