| Newsgroups |
gmane.linux.lfs.beyond.book |
| Message-ID |
<[email protected]> |
#23728: apr-util-1.6.5
-------------------------+-------------------------------
Reporter: Bruce Dubbs | Owner: SecurityAdvisory
Type: enhancement | Status: new
Priority: elevated | Milestone: 98-Security
Component: BOOK | Version: git
Severity: medium | Resolution:
Keywords: |
-------------------------+-------------------------------
Changes (by Joe Locash):
* milestone: 13.1 => 98-Security
* owner: Joe Locash => SecurityAdvisory
* priority: normal => elevated
* severity: normal => medium
* status: assigned => new
Comment:
{{{
Changes with APR-util 1.6.5
*) Fix oracle DBD compilation errors introduced in 1.6.4. PR 70170.
Changes with APR-util 1.6.4
*) SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached
client (cve.mitre.org)
Heap-based Buffer Overflow vulnerability in Apache Portable
Runtime Utility memcached client
This issue affects Apache Portable Runtime Utility: from 1.3.0
through 1.6.3.
Credits: Elhanan Haenel
*) SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap
buffer overflow in APR redis client (cve.mitre.org)
Heap-based Buffer Overflow vulnerability in Apache Portable
Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0
through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes
the issue.
Credits: Elhanan Haenel
*) SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL
Injection in apr_dbd_oracle (cve.mitre.org)
Improper Neutralization of Special Elements used in an SQL
Command ('SQL Injection') vulnerability in Apache Portable
Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0
through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes
the issue.
Credits: Elhanan Haenel
*) SECURITY: CVE-2026-32327: Apache Portable Runtime Utility:
apr-util XML stack recursion crash (cve.mitre.org)
A bug in APR-util version 1.6.3 (and earlier) allows a stack
recursion attack against any library consumer which parses XML
from untrusted sources and uses the apr_xml_quote_elem()
function.
Users are recommended to upgrade to version 1.6.4, which fixes
this issue.
Credits: Younghyo Cho @ CISLab, SeoulTech
*) SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to
timing attack (cve.mitre.org)
APR-util versions 1.6.3 (and earlier) function
apr_password_validate() was not constant-time with regards to
hashes or passwords comparisons, potentially leaking their
content via a side channel timing attack particularly on
platforms without crypt() such as Windows, BeOS, NetWare, or
Android.
Users are recommended to upgrade to version 1.6.4, which fixes
this issue.
Credits: Michael Rowley <michael csirt.global>
*) apr_brigade: Don't split the final LF in apr_brigade_split_line() to
avoid producing an empty bucket. PR 64273
[Barnim Dzwillo <dzwillo strato.de>, Joe Orton]
*) apr_brigade: Metadata buckets are now ignored in
apr_brigade_split_line, apr_brigade_flatten and
apr_brigade_to_iovec, fixing possible undefined behaviour. PR 68278
[Ben Kallus <benjamin.p.kallus.gr dartmouth.edu>, Joe Orton]
*) apr_crypto_openssl: Compatibility with OpenSSL 3. [Yann Ylavic]
*) apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL
on versions 1.1+. [Graham Leggett]
*) apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
[Lubos Uhliarik <luhliari redhat.com>]
*) configure: Fix Berkeley DB detection with compilers enforcing
strict C99 compliance. PR 66396.
[Florian Weimer <fweimer redhat.com>]
}}}
Fixed at [sha:45a6f8f2b3]. Leaving open for SA.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23728#comment:2>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page