Re: [BLFS Trac] #23728: apr-util-1.6.5

BLFS Trac ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23728: apr-util-1.6.5
-------------------------+-------------------------------
 Reporter:  Bruce Dubbs  |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  elevated     |   Milestone:  98-Security
Component:  BOOK         |     Version:  git
 Severity:  medium       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Changes (by Joe Locash):

 * milestone:  13.1 => 98-Security
 * owner:  Joe Locash => SecurityAdvisory
 * priority:  normal => elevated
 * severity:  normal => medium
 * status:  assigned => new

Comment:

 {{{
 Changes with APR-util 1.6.5

   *) Fix oracle DBD compilation errors introduced in 1.6.4. PR 70170.

 Changes with APR-util 1.6.4

   *) SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached
      client (cve.mitre.org)
      Heap-based Buffer Overflow vulnerability in Apache Portable
      Runtime Utility memcached client
      This issue affects Apache Portable Runtime Utility: from 1.3.0
      through 1.6.3.
      Credits: Elhanan Haenel

   *) SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap
      buffer overflow in APR redis client (cve.mitre.org)
      Heap-based Buffer Overflow vulnerability in Apache Portable
      Runtime Utility redis client.
      This issue affects Apache Portable Runtime Utility: from 1.6.0
      through 1.6.3.
      Users are recommended to upgrade to version 1.6.4, which fixes
      the issue.
      Credits: Elhanan Haenel

   *) SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL
      Injection in apr_dbd_oracle (cve.mitre.org)
      Improper Neutralization of Special Elements used in an SQL
      Command ('SQL Injection') vulnerability in Apache Portable
      Runtime Utility via apr_dbd_oracle provider.
      This issue affects Apache Portable Runtime Utility: from 1.6.0
      through 1.6.3.
      Users are recommended to upgrade to version 1.6.4, which fixes
      the issue.
      Credits: Elhanan Haenel

   *) SECURITY: CVE-2026-32327: Apache Portable Runtime Utility:
      apr-util XML stack recursion crash (cve.mitre.org)
      A bug in APR-util version 1.6.3 (and earlier) allows a stack
      recursion attack against any library consumer which parses XML
      from untrusted sources and uses the apr_xml_quote_elem()
      function.
      Users are recommended to upgrade to version 1.6.4, which fixes
      this issue.
      Credits: Younghyo Cho @ CISLab, SeoulTech

   *) SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to
      timing attack (cve.mitre.org)
      APR-util versions 1.6.3 (and earlier) function
      apr_password_validate() was not constant-time with regards to
      hashes or passwords comparisons, potentially leaking their
      content via a side channel timing attack particularly on
      platforms without crypt() such as  Windows, BeOS, NetWare, or
      Android.
      Users are recommended to upgrade to version 1.6.4, which fixes
      this issue.
      Credits: Michael Rowley <michael csirt.global>

   *) apr_brigade: Don't split the final LF in apr_brigade_split_line() to
      avoid producing an empty bucket.  PR 64273
      [Barnim Dzwillo <dzwillo strato.de>, Joe Orton]

   *) apr_brigade: Metadata buckets are now ignored in
      apr_brigade_split_line, apr_brigade_flatten and
      apr_brigade_to_iovec, fixing possible undefined behaviour.  PR 68278
      [Ben Kallus <benjamin.p.kallus.gr dartmouth.edu>, Joe Orton]

   *) apr_crypto_openssl: Compatibility with OpenSSL 3.  [Yann Ylavic]

   *) apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL
      on versions 1.1+. [Graham Leggett]

   *) apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
      [Lubos Uhliarik <luhliari redhat.com>]

   *) configure: Fix Berkeley DB detection with compilers enforcing
      strict C99 compliance.  PR 66396.
      [Florian Weimer <fweimer redhat.com>]
 }}}
 Fixed at [sha:45a6f8f2b3]. Leaving open for SA.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23728#comment:2>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.