Apache Portable Runtime(APR,Apache可移植运行库)是美国阿帕奇(Apache)基金会的一个为上层应用程序提供可跨越多个操作系统平台使用的底层支持接口库。 Apache Portable Runtime 1.7.0及以前版本存在输入验证错误漏洞,该漏洞源于其apr_socket_sendv()函数允许攻击者实现整数溢出导致在栈缓冲区末端之外写入数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Portable Runtime (APR) | 0 ~ 1.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-25147 | Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family | |
| CVE-2022-24963 | Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions | |
| CVE-2022-44644 | Apache Linkis (incubating): The DatasourceManager module has a Local File Read Vulnerabili | |
| CVE-2022-44645 | Apache Linkis (incubating): The DatasourceManager module has a serialization attack vulner | |
| CVE-2023-24829 | Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench |
No comments yet