CVE-2017-12618

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.7 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
apacheportable_runtime_utility
0.9.1
apacheportable_runtime_utility
0.9.2
apacheportable_runtime_utility
0.9.3
apacheportable_runtime_utility
0.9.4
apacheportable_runtime_utility
0.9.5
apacheportable_runtime_utility
0.9.6
apacheportable_runtime_utility
0.9.7
apacheportable_runtime_utility
0.9.9
apacheportable_runtime_utility
0.9.10
apacheportable_runtime_utility
0.9.11
apacheportable_runtime_utility
0.9.12
apacheportable_runtime_utility
0.9.13
apacheportable_runtime_utility
0.9.14
apacheportable_runtime_utility
0.9.15
apacheportable_runtime_utility
0.9.16
apacheportable_runtime_utility
0.9.17
apacheportable_runtime_utility
0.9.18
apacheportable_runtime_utility
0.9.19
apacheportable_runtime_utility
0.9.20
apacheportable_runtime_utility
1.0.0
apacheportable_runtime_utility
1.0.1
apacheportable_runtime_utility
1.0.2
apacheportable_runtime_utility
1.1.0
apacheportable_runtime_utility
1.1.1
apacheportable_runtime_utility
1.1.2
apacheportable_runtime_utility
1.2.1
apacheportable_runtime_utility
1.2.2
apacheportable_runtime_utility
1.2.6
apacheportable_runtime_utility
1.2.7
apacheportable_runtime_utility
1.2.8
apacheportable_runtime_utility
1.2.9
apacheportable_runtime_utility
1.2.10
apacheportable_runtime_utility
1.2.12
apacheportable_runtime_utility
1.2.13
apacheportable_runtime_utility
1.3.0
apacheportable_runtime_utility
1.3.1
apacheportable_runtime_utility
1.3.2
apacheportable_runtime_utility
1.3.3
apacheportable_runtime_utility
1.3.4
apacheportable_runtime_utility
1.3.5
apacheportable_runtime_utility
1.3.6
apacheportable_runtime_utility
1.3.7
apacheportable_runtime_utility
1.3.8
apacheportable_runtime_utility
1.3.9
apacheportable_runtime_utility
1.3.10
apacheportable_runtime_utility
1.3.11
apacheportable_runtime_utility
1.3.12
apacheportable_runtime_utility
1.3.13
apacheportable_runtime_utility
1.4.0
apacheportable_runtime_utility
1.4.1
apacheportable_runtime_utility
1.4.2
apacheportable_runtime_utility
1.4.3
apacheportable_runtime_utility
1.5.0
apacheportable_runtime_utility
1.5.1
apacheportable_runtime_utility
1.5.2
apacheportable_runtime_utility
1.5.3
apacheportable_runtime_utility
1.5.4
apacheportable_runtime_utility
1.5.5
apacheportable_runtime_utility
1.6.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apr-util
bullseye (security)
1.6.1-5+deb11u1
fixed
bullseye
1.6.1-5+deb11u1
fixed
stretch
no-dsa
jessie
no-dsa
bookworm
1.6.3-1
fixed
sid
1.6.3-3
fixed
trixie
1.6.3-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apr-util
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
ignored
zesty
ignored
xenial
Fixed 1.5.4-1ubuntu0.1~esm1
released
trusty
Fixed 1.5.3-1ubuntu0.1~esm1
released