svn commit: r86582 - release/apr

[email protected]
Newsgroups gmane.comp.apache.apr.cvs
Message-ID <178602021349.3019335.9552729476799690688@svn03-he-fi>
Author: covener
Date: Thu Aug  6 12:43:33 2026
New Revision: 86582

Log:
publishing release apr-util-1.6.4

Deleted:
   release/apr/apr-util-1.6.3.tar.bz2
   release/apr/apr-util-1.6.3.tar.bz2.asc
   release/apr/apr-util-1.6.3.tar.bz2.sha256
   release/apr/apr-util-1.6.3.tar.gz
   release/apr/apr-util-1.6.3.tar.gz.asc
   release/apr/apr-util-1.6.3.tar.gz.sha256
Modified:
   release/apr/CHANGES-APR-UTIL-1.6

Modified: release/apr/CHANGES-APR-UTIL-1.6
==============================================================================
--- release/apr/CHANGES-APR-UTIL-1.6	Thu Aug  6 12:29:27 2026	(r86581)
+++ release/apr/CHANGES-APR-UTIL-1.6	Thu Aug  6 12:43:33 2026	(r86582)
@@ -1,4 +1,78 @@
                                                      -*- coding: utf-8 -*-
+Changes with APR-util 1.6.4
+
+  *) SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached
+     client (cve.mitre.org)
+     Heap-based Buffer Overflow vulnerability in Apache Portable
+     Runtime Utility memcached client
+     This issue affects Apache Portable Runtime Utility: from 1.3.0
+     through 1.6.3.
+     Credits: Elhanan Haenel
+
+  *) SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap
+     buffer overflow in APR redis client (cve.mitre.org)
+     Heap-based Buffer Overflow vulnerability in Apache Portable
+     Runtime Utility redis client.
+     This issue affects Apache Portable Runtime Utility: from 1.6.0
+     through 1.6.3.
+     Users are recommended to upgrade to version 1.6.4, which fixes
+     the issue.
+     Credits: Elhanan Haenel
+
+  *) SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL
+     Injection in apr_dbd_oracle (cve.mitre.org)
+     Improper Neutralization of Special Elements used in an SQL
+     Command ('SQL Injection') vulnerability in Apache Portable
+     Runtime Utility via apr_dbd_oracle provider.
+     This issue affects Apache Portable Runtime Utility: from 1.6.0
+     through 1.6.3.
+     Users are recommended to upgrade to version 1.6.4, which fixes
+     the issue.
+     Credits: Elhanan Haenel
+
+  *) SECURITY: CVE-2026-32327: Apache Portable Runtime Utility:
+     apr-util XML stack recursion crash (cve.mitre.org)
+     A bug in APR-util version 1.6.3 (and earlier) allows a stack
+     recursion attack against any library consumer which parses XML
+     from untrusted sources and uses the apr_xml_quote_elem()
+     function.
+     Users are recommended to upgrade to version 1.6.4, which fixes
+     this issue.
+     Credits: Younghyo Cho @ CISLab, SeoulTech
+
+  *) SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to
+     timing attack (cve.mitre.org)
+     APR-util versions 1.6.3 (and earlier) function
+     apr_password_validate() was not constant-time with regards to
+     hashes or passwords comparisons, potentially leaking their
+     content via a side channel timing attack particularly on
+     platforms without crypt() such as  Windows, BeOS, NetWare, or
+     Android.
+     Users are recommended to upgrade to version 1.6.4, which fixes
+     this issue.
+     Credits: Michael Rowley <michael csirt.global>
+
+  *) apr_brigade: Don't split the final LF in apr_brigade_split_line() to
+     avoid producing an empty bucket.  PR 64273
+     [Barnim Dzwillo <dzwillo strato.de>, Joe Orton]
+
+  *) apr_brigade: Metadata buckets are now ignored in
+     apr_brigade_split_line, apr_brigade_flatten and
+     apr_brigade_to_iovec, fixing possible undefined behaviour.  PR 68278
+     [Ben Kallus <benjamin.p.kallus.gr dartmouth.edu>, Joe Orton]
+
+  *) apr_crypto_openssl: Compatibility with OpenSSL 3.  [Yann Ylavic]
+
+  *) apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL
+     on versions 1.1+. [Graham Leggett]
+
+  *) apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
+     [Lubos Uhliarik <luhliari redhat.com>]
+
+  *) configure: Fix Berkeley DB detection with compilers enforcing
+     strict C99 compliance.  PR 66396.
+     [Florian Weimer <fweimer redhat.com>]
+
 Changes with APR-util 1.6.3
 
   *) Correct a packaging issue in 1.6.2. The contents of the release were
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.