Information disclosure in Apache Portable Runtime - CVE-2017-12618

 

Information disclosure in Apache Portable Runtime - CVE-2017-12618

Published: October 31, 2018


Vulnerability identifier: #VU15618
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12618
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to an out-of-bounds array dereference in the apr_time_exp_get() function. A remote attacker can access prior out-of-bounds memory, reveal the contents of a different static heap value and read arbitrary files or cause the application to crash.

Affected software

Apache Portable Runtime
Arch Linux
Amazon Linux AMI
macOS
Ubuntu
Fedora
Tivoli Network Manager IP Edition
IBM Engineering Requirements Management DOORS Next
IBM API Connect
libaprutil1 (Ubuntu package)
apr-util

How to mitigate CVE-2017-12618

Update to version 1.6.3.

IBM API Connect - update to 5.0.8.12
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
libaprutil1 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
apr-util - addressed in versions 1.5.4-4.fc25, 1.5.4-6.fc26

External References

Related Security Bulletins