Lucene search

K
ubuntuUbuntuUSN-5885-1
HistoryFeb 27, 2023 - 12:00 a.m.

APR vulnerability

2023-02-2700:00:00
ubuntu.com
49
apr
integer overflow
vulnerability
ubuntu
memory corruption
denial of service
arbitrary code
remote attacker
apache portable runtime

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

10 High

AI Score

Confidence

High

0.059 Low

EPSS

Percentile

93.5%

Releases

  • Ubuntu 22.10
  • Ubuntu 22.04 LTS

Packages

  • apr - Apache Portable Runtime Library

Details

Ronald Crane discovered integer overflow vulnerabilities in the Apache
Portable Runtime (APR) that could potentially result in memory corruption.
A remote attacker could possibly use these issues to cause a denial of
service or execute arbitary code.

OSVersionArchitecturePackageVersionFilename
Ubuntu22.10noarchlibapr1< 1.7.0-8ubuntu0.22.10.1UNKNOWN
Ubuntu22.10noarchlibapr1-dbgsym< 1.7.0-8ubuntu0.22.10.1UNKNOWN
Ubuntu22.10noarchlibapr1-dev< 1.7.0-8ubuntu0.22.10.1UNKNOWN
Ubuntu22.04noarchlibapr1< 1.7.0-8ubuntu0.22.04.1UNKNOWN
Ubuntu22.04noarchlibapr1-dbgsym< 1.7.0-8ubuntu0.22.04.1UNKNOWN
Ubuntu22.04noarchlibapr1-dev< 1.7.0-8ubuntu0.22.04.1UNKNOWN

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

10 High

AI Score

Confidence

High

0.059 Low

EPSS

Percentile

93.5%