CVE-2021-35940 - CVE House
Back to Database
Status published High CVE-2021-35940

Regression of CVE-2017-12613

Vulnerability Description

An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-35940

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • The Apache Portable Runtime project would like to thank Iveta Cesalova (Red Hat) for reporting this issue.

References

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Portable Runtime (APR)
Vulnerable Versions:
Apache Portable Runtime 1.7.0

Timeline

Official Publish: August 23rd, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.