Bug#1143837: apr-util: CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34501 CVE-2026-34502
Salvatore Bonaccorso <[email protected]>
| Newsgroups | gmane.linux.debian.devel.apache |
|---|---|
| Message-ID | <178607720186.912060.2953767430611825949.reportbug__16612.6019366615$1786077326$gmane$org@eldamar.lan> |
Source: apr-util Version: 1.6.3-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerabilities were published for apr-util. CVE-2025-49506[0]: | APR-util versions 1.6.3 (and earlier) function | apr_password_validate() was not constant-time with regards to hashes | or passwords comparisons, potentially leaking their content via a | side channel timing attack particularly on platforms without crypt() | such as Windows, BeOS, NetWare, or Android. Users are recommended | to upgrade to version 1.6.4, which fixes this issue. CVE-2026-32327[1]: | A bug in APR-util version 1.6.3 (and earlier) allows a stack | recursion attack against any library consumer which parses XML from | untrusted sources and uses the apr_xml_quote_elem() function. Users | are recommended to upgrade to version 1.6.4, which fixes this issue. CVE-2026-34191[2]: | Improper Neutralization of Special Elements used in an SQL Command | ('SQL Injection') vulnerability in Apache Portable Runtime Utility | via apr_dbd_oracle provider. This issue affects Apache Portable | Runtime Utility: from 1.6.0 through 1.6.3 CVE-2026-34501[3]: | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime | Utility redis client. This issue affects Apache Portable Runtime | Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade | to version 1.6.4, which fixes the issue. CVE-2026-34502[4]: | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime | Utility memcached client This issue affects Apache Portable Runtime | Utility: from 1.3.0 through 1.6.3. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2025-49506 https://www.cve.org/CVERecord?id=CVE-2025-49506 [1] https://security-tracker.debian.org/tracker/CVE-2026-32327 https://www.cve.org/CVERecord?id=CVE-2026-32327 [2] https://security-tracker.debian.org/tracker/CVE-2026-34191 https://www.cve.org/CVERecord?id=CVE-2026-34191 [3] https://security-tracker.debian.org/tracker/CVE-2026-34501 https://www.cve.org/CVERecord?id=CVE-2026-34501 [4] https://security-tracker.debian.org/tracker/CVE-2026-34502 https://www.cve.org/CVERecord?id=CVE-2026-34502 Regards, Salvatore