[prev in list] [next in list] [prev in thread] [next in thread] 

List:       apr-dev
Subject:    CVE-2021-35940: Apache Portable Runtime (APR): Regression of CVE-2017-12613
From:       Joe Orton <jorton () apache ! org>
Date:       2021-08-23 10:24:50
Message-ID: YSN3cgWxtK8+/LWM () redhat ! com
[Download RAW message or body]

Description:

An out-of-bounds array read in the apr_time_exp*() functions was fixed 
in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613).  The fix 
for this issue was not carried forward to the APR 1.7.x branch, and 
hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the 
same issue.

The patch below addresses the issue: 
https://downloads.apache.org/apr/patches/apr-1.7.0-CVE-2021-35940.patch

Credit:

The Apache Portable Runtime project would like to thank Iveta Cesalova 
(Red Hat) for reporting this issue.

References:

http://svn.apache.org/viewvc?view=revision&revision=1891198 
http://mail-archives.apache.org/mod_mbox/www-announce/201710.mbox/%3CCACsi251B8UaLvM-rrH9fv57-zWi0zhyF3275_jPg1a9VEVVoxw@mail.gmail.com%3E
 https://downloads.apache.org/apr/patches/apr-1.7.0-CVE-2021-35940.patch


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic