apr: Out-of-bounds array deref in apr_time_exp*() functions
Published Oct 24, 2017
7.1
HIGHCVSS 3.1
EPSS 1.75%
Description
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
Affected products
-
- Version 1.6.2 and priorStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Portable Runtime | n/a |
|
Configuration 1
- < 1.7.0
Configuration 2
- 7.0
- 9.0
Configuration 3
- n/a
- 1.0
- 3.0.0
- 1.0
- 6.0
- 7.0
- 6.7
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 6.0
- 7.0
- 6.4
- 6.5
- 6.6
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 6.6
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 6.0
- 7.0
No data.
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.23-125.jbcs.el6
Fixed · RHSA-2017:3477
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_bmx-0:0.9.6-15.GA.jbcs.el6
Fixed · RHSA-2017:3477
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_1.jbcs.el6
Fixed · RHSA-2017:3477
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.23-125.jbcs.el7
Fixed · RHSA-2017:3476
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_bmx-0:0.9.6-15.GA.jbcs.el7
Fixed · RHSA-2017:3476
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_1.jbcs.el7
Fixed · RHSA-2017:3476
Red Hat Enterprise Linux 6
apr-0:1.3.9-5.el6_9.1
Fixed · RHSA-2017:3270
Red Hat Enterprise Linux 6.4 Advanced Update Support
apr-0:1.3.9-5.el6_4.1
Fixed · RHSA-2018:1253
Red Hat Enterprise Linux 6.5 Advanced Update Support
apr-0:1.3.9-5.el6_5.1
Fixed · RHSA-2018:1253
Red Hat Enterprise Linux 6.6 Advanced Update Support
apr-0:1.3.9-5.el6_6.1
Fixed · RHSA-2018:1253
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
apr-0:1.3.9-5.el6_6.1
Fixed · RHSA-2018:1253
Red Hat Enterprise Linux 6.7 Extended Update Support
apr-0:1.3.9-5.el6_7.1
Fixed · RHSA-2018:1253
Red Hat Enterprise Linux 7
apr-0:1.4.8-3.el7_4.1
Fixed · RHSA-2017:3270
Red Hat Enterprise Linux 7.2 Advanced Update Support
apr-0:1.4.8-3.el7_2.1
Fixed · RHSA-2018:1253
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
apr-0:1.4.8-3.el7_2.1
Fixed · RHSA-2018:1253
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
apr-0:1.4.8-3.el7_2.1
Fixed · RHSA-2018:1253
Red Hat Enterprise Linux 7.3 Extended Update Support
apr-0:1.4.8-3.el7_3.1
Fixed · RHSA-2018:1253
Red Hat JBoss Core Services
n/a
Fixed · RHSA-2017:3475
Red Hat JBoss Web Server 3 for RHEL 6
mod_cluster-0:1.3.8-2.Final_redhat_2.1.ep7.el6
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3 for RHEL 6
tomcat-native-0:1.2.8-11.redhat_11.ep7.el6
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3 for RHEL 6
tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3 for RHEL 6
tomcat7-0:7.0.70-25.ep7.el6
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3 for RHEL 6
tomcat8-0:8.0.36-29.ep7.el6
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3 for RHEL 7
mod_cluster-0:1.3.8-2.Final_redhat_2.1.ep7.el7
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3 for RHEL 7
tomcat-native-0:1.2.8-11.redhat_11.ep7.el7
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3 for RHEL 7
tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3 for RHEL 7
tomcat7-0:7.0.70-25.ep7.el7
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3 for RHEL 7
tomcat8-0:8.0.36-29.ep7.el7
Fixed · RHSA-2018:0466
Red Hat JBoss Web Server 3.1
n/a
Fixed · RHSA-2018:0465
Red Hat Software Collections for Red Hat Enterprise Linux 6
httpd24-apr-0:1.5.1-1.el6.1
Fixed · RHSA-2018:0316
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
httpd24-apr-0:1.5.1-1.el6.1
Fixed · RHSA-2018:0316
Red Hat Enterprise Linux 5
apr
Will not fix
Red Hat JBoss Enterprise Application Platform 6
httpd
Affected
Red Hat JBoss Enterprise Web Server 3
apr
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.23-125.jbcs.el6 | Fixed | RHSA-2017:3477 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_bmx-0:0.9.6-15.GA.jbcs.el6 | Fixed | RHSA-2017:3477 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_1.jbcs.el6 | Fixed | RHSA-2017:3477 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.23-125.jbcs.el7 | Fixed | RHSA-2017:3476 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_bmx-0:0.9.6-15.GA.jbcs.el7 | Fixed | RHSA-2017:3476 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_1.jbcs.el7 | Fixed | RHSA-2017:3476 |
| Red Hat Enterprise Linux 6 | apr-0:1.3.9-5.el6_9.1 | Fixed | RHSA-2017:3270 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | apr-0:1.3.9-5.el6_4.1 | Fixed | RHSA-2018:1253 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | apr-0:1.3.9-5.el6_5.1 | Fixed | RHSA-2018:1253 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | apr-0:1.3.9-5.el6_6.1 | Fixed | RHSA-2018:1253 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | apr-0:1.3.9-5.el6_6.1 | Fixed | RHSA-2018:1253 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | apr-0:1.3.9-5.el6_7.1 | Fixed | RHSA-2018:1253 |
| Red Hat Enterprise Linux 7 | apr-0:1.4.8-3.el7_4.1 | Fixed | RHSA-2017:3270 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | apr-0:1.4.8-3.el7_2.1 | Fixed | RHSA-2018:1253 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | apr-0:1.4.8-3.el7_2.1 | Fixed | RHSA-2018:1253 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | apr-0:1.4.8-3.el7_2.1 | Fixed | RHSA-2018:1253 |
| Red Hat Enterprise Linux 7.3 Extended Update Support | apr-0:1.4.8-3.el7_3.1 | Fixed | RHSA-2018:1253 |
| Red Hat JBoss Core Services | n/a | Fixed | RHSA-2017:3475 |
| Red Hat JBoss Web Server 3 for RHEL 6 | mod_cluster-0:1.3.8-2.Final_redhat_2.1.ep7.el6 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat-native-0:1.2.8-11.redhat_11.ep7.el6 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat7-0:7.0.70-25.ep7.el6 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat8-0:8.0.36-29.ep7.el6 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3 for RHEL 7 | mod_cluster-0:1.3.8-2.Final_redhat_2.1.ep7.el7 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat-native-0:1.2.8-11.redhat_11.ep7.el7 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat7-0:7.0.70-25.ep7.el7 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat8-0:8.0.36-29.ep7.el7 | Fixed | RHSA-2018:0466 |
| Red Hat JBoss Web Server 3.1 | n/a | Fixed | RHSA-2018:0465 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | httpd24-apr-0:1.5.1-1.el6.1 | Fixed | RHSA-2018:0316 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | httpd24-apr-0:1.5.1-1.el6.1 | Fixed | RHSA-2018:0316 |
| Red Hat Enterprise Linux 5 | apr | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | httpd | Affected | n/a |
| Red Hat JBoss Enterprise Web Server 3 | apr | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
AV:L/AC:L/Au:N/C:P/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.75% (0.01749) | 77.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.75% (0.01749) | 74.83th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.22% (0.00219) | 42.47th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00063) | 29.23th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.06% (0.00063) | 27.20th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00063) | 25.19th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.05% (0.03052) | 83.71th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.05% (0.03052) | 82.04th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.05% (0.03052) | 64.53th | v2 (v2022.01.01) |
| Feb 3, 2022 | 14.92% (0.14918) | 89.97th | v1 |
| Jan 25, 2022 | 14.92% (0.14918) | 89.94th | v1 |
| Jan 6, 2022 | 14.33% (0.14333) | 89.35th | v1 |
| Oct 11, 2021 | 14.33% (0.14333) | 96.78th | v1 |
| Sep 17, 2021 | 42.88% (0.42880) | 99.37th | v1 |
| Sep 2, 2021 | 41.68% (0.41681) | 99.31th | v1 |
| Sep 1, 2021 | 13.74% (0.13741) | 96.05th | v1 |
| Aug 24, 2021 | 13.74% (0.13741) | 0.00th | v1 |
| Aug 21, 2021 | 11.91% (0.11913) | 0.00th | v1 |
| Aug 17, 2021 | 11.29% (0.11287) | 0.00th | v1 |
| Apr 14, 2021 | 10.65% (0.10652) | 0.00th | v1 |
References (25)
- http://www.apache.org/dist/apr/Announcement1.x.html x_refsource_CONFIRMRelease NotesVendor Advisory
- http://www.openwall.com/lists/oss-security/2021/08/23/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/101560 vdb-entryx_refsource_BIDBroken Link
- http://www.securitytracker.com/id/1042004 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:3270 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3475 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3476 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3477 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0316 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0465 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1253 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-12613 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1506523 Issue Tracking
- https://lists.apache.org/thread.html/12489f2e4a9f9d390235c16298aca0d20658789de80d553513977f13%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLISTIssue TrackingVendor Advisory
- https://lists.apache.org/thread.html/r270dd5022db194b78acaf509216a33c85f3da43757defa05cc766339%40%3Ccommits.apr.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ra2868b53339a6af65577146ad87016368c138388b09bff9d2860f50e%40%3Cdev.apr.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ra38094406cc38a05218ebd1158187feda021b0c3a1df400bbf296af8%40%3Cdev.apr.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb1f3c85f50fbd924a0051675118d1609e57957a02ece7facb723155b%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rcc48a0acebbd74bbdeebc02ff228bb72c0631b21823fffe27d4691e9%40%3Ccommits.apr.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2017/11/msg00005.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00023.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-12613
- https://svn.apache.org/viewvc?view=revision&revision=1807976 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-12613
Change history (0)
No recorded changes yet.