UBUNTU-CVE-2021-35940
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-35940
UBUNTU-CVE-2021-35940
Summary:
Details: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
References: https://ubuntu.com/security/CVE-2021-35940, https://www.openwall.com/lists/oss-security/2021/08/23/1, http://svn.apache.org/viewvc?view=revision&revision=1891198, https://dist.apache.org/repos/dist/release/apr/patches/apr-1.7.0-CVE-2021-35940.patch, http://mail-archives.apache.org/mod_mbox/www-announce/201710.mbox/%3CCACsi251B8UaLvM-rrH9fv57-zWi0zhyF3275_jPg1a9VEVVoxw@mail.gmail.com%3E, https://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e%40%3Cdev.apr.apache.org%3E, http://www.openwall.com/lists/oss-security/2021/08/23/1, https://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e@%3Cdev.apr.apache.org%3E, https://lists.apache.org/thread.html/rb1f3c85f50fbd924a0051675118d1609e57957a02ece7facb723155b@%3Cannounce.apache.org%3E, https://ubuntu.com/security/notices/USN-5056-1, https://www.cve.org/CVERecord?id=CVE-2021-35940
Affected packages
Package
Name: apr
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
