VYPR
High severity7.1NVD Advisory· Published Aug 23, 2021· Updated Jun 17, 2026

CVE-2021-35940

CVE-2021-35940

Description

An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:apache:portable_runtime:1.7.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apache:portable_runtime:1.7.0:*:*:*:*:*:*:*
    • (no CPE)range: 1.7.0
    • (no CPE)range: Apache Portable Runtime 1.7.0
  • cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
  • osv-coords2 versions
    >= 1.7.0, < 1.7.1+ 1 more
    • (no CPE)range: >= 1.7.0, < 1.7.1
    • (no CPE)range: < 1.7.0-4.1

Patches

Vulnerability mechanics

References

16

News mentions

0

No linked articles in our index yet.