Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-49582


Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.


Published

2024-08-26T14:15:07.050

Last Modified

2025-03-13T15:15:39.267

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache portable_runtime < 1.7.5 Yes

References