Description
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
Published: 2017-10-24
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-1163-1 apr-util security update
EUVD EUVD EUVD-2017-4172 Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
Ubuntu USN Ubuntu USN USN-5737-1 APR-util vulnerability
History

No history.

Subscriptions

Apache Portable Runtime Utility
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-05T18:43:56.405Z

Reserved: 2017-08-07T00:00:00.000Z

Link: CVE-2017-12618

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-10-24T01:29:02.030

Modified: 2026-05-13T00:24:29.033

Link: CVE-2017-12618

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-10-23T00:00:00Z

Links: CVE-2017-12618 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses