← Vulnerability feed

Vulnerability record · CVE-2023-49582 · published 26 August 2024

CVE-2023-49582: Apache portable runtime incorrect permission assignment vulnerability

Apache · Portable Runtime

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.

5.5 CVSS 3.1 Medium EPSS 0.33% · top 76.1% CWE-732 · Incorrect permission assignment
5.5CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h) Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-49582 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-2412Apache apr-util vulnerabilityMultiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow …EPSS 14%9.8CVE-2022-24963Apache portable runtime integer overflow vulnerabilityInteger Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a …EPSS 1.5%9.8CVE-2022-28331Apache portable runtime integer overflow vulnerabilityOn Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of int…EPSS 1.6%7.5CVE-2009-2699Apache http server vulnerabilityThe Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the A…EPSS 14%7.1CVE-2021-35940Apache portable runtime out-of-bounds read vulnerabilityAn out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for thi…EPSS 1.2%7.1CVE-2017-12613Apache portable runtime out-of-bounds read vulnerabilityWhen apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, ou…EPSS 1.7%5.0CVE-2012-0840Apache portable runtime improper input validation vulnerabilitytables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash col…EPSS 42%4.3CVE-2011-0419Apache portable runtime allocation without limits vulnerabilityStack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apac…EPSS 30%

Source: NIST National Vulnerability Database (record CVE-2023-49582), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.