Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data.
This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h)
Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apr | Oct 1, 2024 | Aug 26, 2024 |
| Amazon Linux Ami 2 | — | Upgrade aprUpgrade apr-develUpgrade apr-debuginfo | Dec 20, 2024 | Aug 26, 2024 |
| Amazon_linux_2023 | — | Upgrade aprUpgrade apr-debuginfoUpgrade apr-debugsourceUpgrade apr-devel | Feb 17, 2025 | Aug 26, 2024 |
| Debian | — | Upgrade apr | Nov 11, 2024 | Aug 26, 2024 |
| Ubuntu | — | Upgrade libapr1-dev (Ubuntu Pro)Upgrade libapr1Upgrade libapr1-devUpgrade libapr1t64Upgrade libapr1 (Ubuntu Pro) | Sep 30, 2024 | Aug 26, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 26, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub