svn commit: r86582 - release/apr
| Newsgroups | gmane.comp.apache.apr.cvs |
|---|---|
| Message-ID | <178602021349.3019335.9552729476799690688@svn03-he-fi> |
Author: covener
Date: Thu Aug 6 12:43:33 2026
New Revision: 86582
Log:
publishing release apr-util-1.6.4
Deleted:
release/apr/apr-util-1.6.3.tar.bz2
release/apr/apr-util-1.6.3.tar.bz2.asc
release/apr/apr-util-1.6.3.tar.bz2.sha256
release/apr/apr-util-1.6.3.tar.gz
release/apr/apr-util-1.6.3.tar.gz.asc
release/apr/apr-util-1.6.3.tar.gz.sha256
Modified:
release/apr/CHANGES-APR-UTIL-1.6
Modified: release/apr/CHANGES-APR-UTIL-1.6
==============================================================================
--- release/apr/CHANGES-APR-UTIL-1.6 Thu Aug 6 12:29:27 2026 (r86581)
+++ release/apr/CHANGES-APR-UTIL-1.6 Thu Aug 6 12:43:33 2026 (r86582)
@@ -1,4 +1,78 @@
-*- coding: utf-8 -*-
+Changes with APR-util 1.6.4
+
+ *) SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached
+ client (cve.mitre.org)
+ Heap-based Buffer Overflow vulnerability in Apache Portable
+ Runtime Utility memcached client
+ This issue affects Apache Portable Runtime Utility: from 1.3.0
+ through 1.6.3.
+ Credits: Elhanan Haenel
+
+ *) SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap
+ buffer overflow in APR redis client (cve.mitre.org)
+ Heap-based Buffer Overflow vulnerability in Apache Portable
+ Runtime Utility redis client.
+ This issue affects Apache Portable Runtime Utility: from 1.6.0
+ through 1.6.3.
+ Users are recommended to upgrade to version 1.6.4, which fixes
+ the issue.
+ Credits: Elhanan Haenel
+
+ *) SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL
+ Injection in apr_dbd_oracle (cve.mitre.org)
+ Improper Neutralization of Special Elements used in an SQL
+ Command ('SQL Injection') vulnerability in Apache Portable
+ Runtime Utility via apr_dbd_oracle provider.
+ This issue affects Apache Portable Runtime Utility: from 1.6.0
+ through 1.6.3.
+ Users are recommended to upgrade to version 1.6.4, which fixes
+ the issue.
+ Credits: Elhanan Haenel
+
+ *) SECURITY: CVE-2026-32327: Apache Portable Runtime Utility:
+ apr-util XML stack recursion crash (cve.mitre.org)
+ A bug in APR-util version 1.6.3 (and earlier) allows a stack
+ recursion attack against any library consumer which parses XML
+ from untrusted sources and uses the apr_xml_quote_elem()
+ function.
+ Users are recommended to upgrade to version 1.6.4, which fixes
+ this issue.
+ Credits: Younghyo Cho @ CISLab, SeoulTech
+
+ *) SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to
+ timing attack (cve.mitre.org)
+ APR-util versions 1.6.3 (and earlier) function
+ apr_password_validate() was not constant-time with regards to
+ hashes or passwords comparisons, potentially leaking their
+ content via a side channel timing attack particularly on
+ platforms without crypt() such as Windows, BeOS, NetWare, or
+ Android.
+ Users are recommended to upgrade to version 1.6.4, which fixes
+ this issue.
+ Credits: Michael Rowley <michael csirt.global>
+
+ *) apr_brigade: Don't split the final LF in apr_brigade_split_line() to
+ avoid producing an empty bucket. PR 64273
+ [Barnim Dzwillo <dzwillo strato.de>, Joe Orton]
+
+ *) apr_brigade: Metadata buckets are now ignored in
+ apr_brigade_split_line, apr_brigade_flatten and
+ apr_brigade_to_iovec, fixing possible undefined behaviour. PR 68278
+ [Ben Kallus <benjamin.p.kallus.gr dartmouth.edu>, Joe Orton]
+
+ *) apr_crypto_openssl: Compatibility with OpenSSL 3. [Yann Ylavic]
+
+ *) apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL
+ on versions 1.1+. [Graham Leggett]
+
+ *) apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
+ [Lubos Uhliarik <luhliari redhat.com>]
+
+ *) configure: Fix Berkeley DB detection with compilers enforcing
+ strict C99 compliance. PR 66396.
+ [Florian Weimer <fweimer redhat.com>]
+
Changes with APR-util 1.6.3
*) Correct a packaging issue in 1.6.2. The contents of the release were