UBUNTU-CVE-2017-12618
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-12618
UBUNTU-CVE-2017-12618
Summary:
Details: Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
References: https://ubuntu.com/security/CVE-2017-12618, http://mail-archives.apache.org/mod_mbox/apr-dev/201710.mbox/%3CCACsi252POs4toeJJciwg09_eu2cO3XFg%3DUqsPjXsfjDoeC3-UQ%40mail.gmail.com%3E, https://ubuntu.com/security/notices/USN-5737-1, https://www.cve.org/CVERecord?id=CVE-2017-12618
Affected packages
Package
Name: apr-util
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
