First published: Tue Oct 24 2017(Updated: )
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
Credit: security@apache.org Craig Young Tripwire VERT
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Mojave | <10.14.1 | 10.14.1 |
macOS High Sierra | ||
macOS High Sierra | ||
macOS Mojave | <10.14 | 10.14 |
IBM Engineering Requirements Management DOORS Web Access | <=9.7.2.8 | |
IBM Rational DOORS Web Access | <=9.7.2.8 | |
IBM Rational DOORS | <=9.6.1.x | |
Apache Portable Runtime | =0.9.1 | |
Apache Portable Runtime | =0.9.2 | |
Apache Portable Runtime | =0.9.3 | |
Apache Portable Runtime | =0.9.4 | |
Apache Portable Runtime | =0.9.5 | |
Apache Portable Runtime | =0.9.6 | |
Apache Portable Runtime | =0.9.7 | |
Apache Portable Runtime | =0.9.9 | |
Apache Portable Runtime | =0.9.10 | |
Apache Portable Runtime | =0.9.11 | |
Apache Portable Runtime | =0.9.12 | |
Apache Portable Runtime | =0.9.13 | |
Apache Portable Runtime | =0.9.14 | |
Apache Portable Runtime | =0.9.15 | |
Apache Portable Runtime | =0.9.16 | |
Apache Portable Runtime | =0.9.17 | |
Apache Portable Runtime | =0.9.18 | |
Apache Portable Runtime | =0.9.19 | |
Apache Portable Runtime | =0.9.20 | |
Apache Portable Runtime | =1.0.0 | |
Apache Portable Runtime | =1.0.1 | |
Apache Portable Runtime | =1.0.2 | |
Apache Portable Runtime | =1.1.0 | |
Apache Portable Runtime | =1.1.1 | |
Apache Portable Runtime | =1.1.2 | |
Apache Portable Runtime | =1.2.1 | |
Apache Portable Runtime | =1.2.2 | |
Apache Portable Runtime | =1.2.6 | |
Apache Portable Runtime | =1.2.7 | |
Apache Portable Runtime | =1.2.8 | |
Apache Portable Runtime | =1.2.9 | |
Apache Portable Runtime | =1.2.10 | |
Apache Portable Runtime | =1.2.12 | |
Apache Portable Runtime | =1.2.13 | |
Apache Portable Runtime | =1.3.0 | |
Apache Portable Runtime | =1.3.1 | |
Apache Portable Runtime | =1.3.2 | |
Apache Portable Runtime | =1.3.3 | |
Apache Portable Runtime | =1.3.4 | |
Apache Portable Runtime | =1.3.5 | |
Apache Portable Runtime | =1.3.6 | |
Apache Portable Runtime | =1.3.7 | |
Apache Portable Runtime | =1.3.8 | |
Apache Portable Runtime | =1.3.9 | |
Apache Portable Runtime | =1.3.10 | |
Apache Portable Runtime | =1.3.11 | |
Apache Portable Runtime | =1.3.12 | |
Apache Portable Runtime | =1.3.13 | |
Apache Portable Runtime | =1.4.0 | |
Apache Portable Runtime | =1.4.1 | |
Apache Portable Runtime | =1.4.2 | |
Apache Portable Runtime | =1.4.3 | |
Apache Portable Runtime | =1.5.0 | |
Apache Portable Runtime | =1.5.1 | |
Apache Portable Runtime | =1.5.2 | |
Apache Portable Runtime | =1.5.3 | |
Apache Portable Runtime | =1.5.4 | |
Apache Portable Runtime | =1.5.5 | |
Apache Portable Runtime | =1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-12618 is considered to have a moderate severity level due to the potential for a local user to cause application crashes.
To fix CVE-2017-12618, upgrade the Apache Portable Runtime Utility to version 1.6.1 or later.
CVE-2017-12618 affects versions of Apache Portable Runtime Utility from 1.6.0 and prior.
Exploiting CVE-2017-12618 could allow a local user to manipulate the SDBM database files leading to application crashes.
Any local user with write access to the SDBM database files of applications using the Apache Portable Runtime Utility is impacted by CVE-2017-12618.