An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-apr | Aug 22, 2024 | Aug 23, 2021 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-apramazon-linux-ami-2-upgrade-apr-debuginfoamazon-linux-ami-2-upgrade-apr-devel | Feb 16, 2023 | Aug 23, 2021 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-apramazon-linux-2023-upgrade-apr-debuginfoamazon-linux-2023-upgrade-apr-debugsourceamazon-linux-2023-upgrade-apr-devel | Feb 17, 2025 | Aug 23, 2021 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Aug 23, 2021 | |
| Debian | debian-upgrade-apr | Jul 30, 2024 | Aug 23, 2021 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-library-apr-1-1-7-0-11-4-39-0-1-107-0 | Nov 17, 2021 | Aug 23, 2021 | |
| Ubuntu | ubuntu-pro-upgrade-libapr1ubuntu-upgrade-libapr1 | Aug 31, 2021 | Aug 23, 2021 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Aug 23, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub