Incorrect default permissions in Apache Portable Runtime - CVE-2023-49582

 

Incorrect default permissions in Apache Portable Runtime - CVE-2023-49582

Published: August 26, 2024


Vulnerability identifier: #VU96554
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49582
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to lax permissions set by the Apache Portable Runtime library on Unix platforms. A local user can read the named shared memory segments.


Affected software

Apache Portable Runtime
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Ubuntu
Basesystem Module
openSUSE Leap
Anolis OS
openEuler
Fedora
APEX Cloud Platform for Microsoft Azure
IBM Engineering Requirements Management DOORS Next
EasyApache
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Oracle Financial Services Behavior Detection Platform
Infrastructure Technology
Oracle HTTP Server
Oracle Communications Cloud Native Core Network Repository Function
Communications Unified Assurance
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository
libapr1-dev (Ubuntu package)
libapr1 (Ubuntu package)
libapr1-devel
libapr1-debuginfo
libapr1-debugsource
libapr1
apr-devel
apr-debugsource
libapr1t64 (Ubuntu package)
apr
apr-debuginfo
apr-help
apr-doc
NetWorker Management Console

How to mitigate CVE-2023-49582

Install updates from vendor's website.

Apache Portable Runtime - update to 1.7.5
APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
EasyApache - addressed in versions 4 25-16, 4 2024-8-29
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
libapr1-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 1.6.5-1ubuntu1.1, 1.7.0-8ubuntu0.22.04.2, 1.7.2-3.1ubuntu0.1
libapr1 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.6.5-1ubuntu1.1, 1.7.0-8ubuntu0.22.04.2
libapr1-devel - update to 1.5.1-4.8.1
libapr1-debuginfo - addressed in versions 1.5.1-4.8.1, 1.6.3-150000.3.6.1
libapr1-debugsource - update to 1.5.1-4.8.1
libapr1 - addressed in versions 1.5.1-4.8.1, 1.6.3-150000.3.6.1
apr-devel - update to 1.6.3-150000.3.6.1
apr-debugsource - update to 1.6.3-150000.3.6.1
libapr1t64 (Ubuntu package) - update to 1.7.2-3.1ubuntu0.1
apr - update to 1.7.4-4
apr-debuginfo - update to 1.7.4-4
apr-debugsource - update to 1.7.4-4
apr-devel - update to 1.7.4-4
apr-help - update to 1.7.4-4
apr-devel - update to 1.7.5-1
apr-doc - update to 1.7.5-1
apr - update to 1.7.5-1
apr - addressed in versions 1.7.5-1.fc39, 1.7.5-1.fc40, 1.7.5-1.fc41
NetWorker Management Console - update to 19.12.0.1

External References

Related Security Bulletins