An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apr | Aug 22, 2024 | Aug 23, 2021 |
| Amazon Linux Ami 2 | — | Upgrade aprUpgrade apr-debuginfoUpgrade apr-devel | Feb 16, 2023 | Aug 23, 2021 |
| Amazon_linux_2023 | — | Upgrade apr-debugsourceUpgrade aprUpgrade apr-develUpgrade apr-debuginfo | Feb 17, 2025 | Aug 23, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Aug 23, 2021 |
| Debian | — | Upgrade apr | Jul 30, 2024 | Aug 23, 2021 |
| Oracle Solaris | — | Upgrade library/apr-1 to version 1.7.0-11.4.39.0.1.107.0 on Solaris 11.4 | Nov 17, 2021 | Aug 23, 2021 |
| Ubuntu | — | Upgrade libapr1Upgrade libapr1 (Ubuntu Pro) | Aug 31, 2021 | Aug 23, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 23, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub