https://seclists.org/oss-sec/2024/q3/233: CVE-2023-49582: Apache Portable Runtime (APR): Unexpected lax shad memory permissions
Published Aug 26, 2024
·Updated
Affected Software
1 affected component
Apache Portable Runtime>=0.9.0<1.7.4
Frequently Asked Questions
1
What is the severity of CVE-2023-49582?
The severity of CVE-2023-49582 is classified as moderate.
2
Which versions of Apache Portable Runtime are affected by CVE-2023-49582?
Apache Portable Runtime versions from 0.9.0 through 1.7.4 are affected by CVE-2023-49582.
3
What type of vulnerability is described in CVE-2023-49582?
CVE-2023-49582 involves lax memory permissions in the Apache Portable Runtime library that allow local users to read sensitive data.
4
How can I mitigate CVE-2023-49582?
To mitigate CVE-2023-49582, consider updating to a fixed version of Apache Portable Runtime that addresses the lax permissions issue.
5
What impact does CVE-2023-49582 have on application security?
CVE-2023-49582 can lead to sensitive application data exposure due to improper memory permissions on Unix platforms.