Out-of-bounds read in Apache Portable Runtime - CVE-2021-35940

 

Out-of-bounds read in Apache Portable Runtime - CVE-2021-35940

Published: August 24, 2021 / Updated: February 2, 2023


Vulnerability identifier: #VU56059
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35940
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a boundary condition in the "apr_time_exp*()" functions. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.

Note, the vulnerability exists due to a missing patch for #VU9477 (CVE-2017-12613).


Affected software

Apache Portable Runtime
Amazon Linux AMI
Oracle Solaris
Ubuntu
Slackware Linux
FactoryTalk Edge Gateway
EasyApache
Oracle HTTP Server
libapr1 (Ubuntu package)
apr

How to mitigate CVE-2021-35940

Install update from vendor's website.

Apache Portable Runtime - update to 1.7.1
FactoryTalk Edge Gateway - update to 1.4
EasyApache - update to 4 2021-9-1
libapr1 (Ubuntu package) - update to 1.7.0-6ubuntu0.1
apr - update to 1.7.2
apr - update to 1.7.2-2

External References

Related Security Bulletins