Description

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.

INFO

Published Date :

2024-08-26T14:03:44.588Z

Last Modified :

2025-03-13T14:25:56.517Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2023-49582 vulnerability.

Vendors Products
Apache
  • Portable Runtime

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact