Bug#1143837: apr-util: CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34501 CVE-2026-34502

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.apache
Message-ID <178607720186.912060.2953767430611825949.reportbug__16612.6019366615$1786077326$gmane$org@eldamar.lan>
Source: apr-util
Version: 1.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for apr-util.

CVE-2025-49506[0]:
| APR-util versions 1.6.3 (and earlier) function
| apr_password_validate() was not constant-time with regards to hashes
| or passwords comparisons, potentially leaking their content via a
| side channel timing attack particularly on platforms without crypt()
| such as  Windows, BeOS, NetWare, or Android.  Users are recommended
| to upgrade to version 1.6.4, which fixes this issue.


CVE-2026-32327[1]:
| A bug in APR-util version 1.6.3 (and earlier) allows a stack
| recursion attack against any library consumer which parses XML from
| untrusted sources and uses the apr_xml_quote_elem() function.  Users
| are recommended to upgrade to version 1.6.4, which fixes this issue.


CVE-2026-34191[2]:
| Improper Neutralization of Special Elements used in an SQL Command
| ('SQL Injection') vulnerability in Apache Portable Runtime Utility
| via apr_dbd_oracle provider.  This issue affects Apache Portable
| Runtime Utility: from 1.6.0 through 1.6.3


CVE-2026-34501[3]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility redis client.  This issue affects Apache Portable Runtime
| Utility: from 1.6.0 through 1.6.3.  Users are recommended to upgrade
| to version 1.6.4, which fixes the issue.


CVE-2026-34502[4]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility memcached client  This issue affects Apache Portable Runtime
| Utility: from 1.3.0 through 1.6.3.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-49506
    https://www.cve.org/CVERecord?id=CVE-2025-49506
[1] https://security-tracker.debian.org/tracker/CVE-2026-32327
    https://www.cve.org/CVERecord?id=CVE-2026-32327
[2] https://security-tracker.debian.org/tracker/CVE-2026-34191
    https://www.cve.org/CVERecord?id=CVE-2026-34191
[3] https://security-tracker.debian.org/tracker/CVE-2026-34501
    https://www.cve.org/CVERecord?id=CVE-2026-34501
[4] https://security-tracker.debian.org/tracker/CVE-2026-34502
    https://www.cve.org/CVERecord?id=CVE-2026-34502

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.