Out-of-bounds read in Apache Portable Runtime - CVE-2021-35940
Published: August 24, 2021 / Updated: February 2, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a boundary condition in the "apr_time_exp*()" functions. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.
Note, the vulnerability exists due to a missing patch for #VU9477 (CVE-2017-12613).
Affected software
Amazon Linux AMI
Oracle Solaris
Ubuntu
Slackware Linux
FactoryTalk Edge Gateway
EasyApache
Oracle HTTP Server
libapr1 (Ubuntu package)
apr
How to mitigate CVE-2021-35940
FactoryTalk Edge Gateway - update to 1.4
EasyApache - update to 4 2021-9-1
libapr1 (Ubuntu package) - update to 1.7.0-6ubuntu0.1
apr - update to 1.7.2
apr - update to 1.7.2-2
External References
- http://mail-archives.apache.org/mod_mbox/www-announce/201710.mbox/%3CCACsi251B8UaLvM-rrH9fv57-zWi0zhyF3275_jPg1a9VEVVoxw@mail.gmail.com%3E
- https://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e%40%3Cdev.apr.apache.org%3E
- http://svn.apache.org/viewvc?view=revision&revision=1891198
- https://dist.apache.org/repos/dist/release/apr/patches/apr-1.7.0-CVE-2021-35940.patch
- http://www.openwall.com/lists/oss-security/2021/08/23/1
- https://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e@%3Cdev.apr.apache.org%3E
- https://lists.apache.org/thread.html/rb1f3c85f50fbd924a0051675118d1609e57957a02ece7facb723155b@%3Cannounce.apache.org%3E
Related Security Bulletins
- Out-of-bounds read in Apache Portable Runtime
- Multiple vulnerabilities in cPanel EasyApache
- Ubuntu update for apr
- Multiple vulnerabilities in Oracle HTTP Server
- Slackware Linux update for apr
- Multiple vulnerabilities in Oracle Solaris third-party software
- Out-of-bounds read in Rockwell Automation FactoryTalk Edge Gateway
- Amazon Linux AMI update for apr