Opened 7 weeks ago

Closed 6 weeks ago

#23728 closed enhancement (fixed)

apr-util-1.6.5

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (3)

comment:1 by Joe Locash, 7 weeks ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 7 weeks ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Priority: normal → elevated
Severity: normal → medium
Status: assigned → new
Changes with APR-util 1.6.5

  *) Fix oracle DBD compilation errors introduced in 1.6.4. PR 70170.

Changes with APR-util 1.6.4

  *) SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached
     client (cve.mitre.org)
     Heap-based Buffer Overflow vulnerability in Apache Portable
     Runtime Utility memcached client
     This issue affects Apache Portable Runtime Utility: from 1.3.0
     through 1.6.3.
     Credits: Elhanan Haenel

  *) SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap
     buffer overflow in APR redis client (cve.mitre.org)
     Heap-based Buffer Overflow vulnerability in Apache Portable
     Runtime Utility redis client.
     This issue affects Apache Portable Runtime Utility: from 1.6.0
     through 1.6.3.
     Users are recommended to upgrade to version 1.6.4, which fixes
     the issue.
     Credits: Elhanan Haenel

  *) SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL
     Injection in apr_dbd_oracle (cve.mitre.org)
     Improper Neutralization of Special Elements used in an SQL
     Command ('SQL Injection') vulnerability in Apache Portable
     Runtime Utility via apr_dbd_oracle provider.
     This issue affects Apache Portable Runtime Utility: from 1.6.0
     through 1.6.3.
     Users are recommended to upgrade to version 1.6.4, which fixes
     the issue.
     Credits: Elhanan Haenel

  *) SECURITY: CVE-2026-32327: Apache Portable Runtime Utility:
     apr-util XML stack recursion crash (cve.mitre.org)
     A bug in APR-util version 1.6.3 (and earlier) allows a stack
     recursion attack against any library consumer which parses XML
     from untrusted sources and uses the apr_xml_quote_elem()
     function.
     Users are recommended to upgrade to version 1.6.4, which fixes
     this issue.
     Credits: Younghyo Cho @ CISLab, SeoulTech

  *) SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to
     timing attack (cve.mitre.org)
     APR-util versions 1.6.3 (and earlier) function
     apr_password_validate() was not constant-time with regards to
     hashes or passwords comparisons, potentially leaking their
     content via a side channel timing attack particularly on
     platforms without crypt() such as  Windows, BeOS, NetWare, or
     Android.
     Users are recommended to upgrade to version 1.6.4, which fixes
     this issue.
     Credits: Michael Rowley <michael csirt.global>

  *) apr_brigade: Don't split the final LF in apr_brigade_split_line() to
     avoid producing an empty bucket.  PR 64273
     [Barnim Dzwillo <dzwillo strato.de>, Joe Orton]

  *) apr_brigade: Metadata buckets are now ignored in
     apr_brigade_split_line, apr_brigade_flatten and
     apr_brigade_to_iovec, fixing possible undefined behaviour.  PR 68278
     [Ben Kallus <benjamin.p.kallus.gr dartmouth.edu>, Joe Orton]

  *) apr_crypto_openssl: Compatibility with OpenSSL 3.  [Yann Ylavic]

  *) apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL
     on versions 1.1+. [Graham Leggett]

  *) apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
     [Lubos Uhliarik <luhliari redhat.com>]

  *) configure: Fix Berkeley DB detection with compilers enforcing
     strict C99 compliance.  PR 66396.
     [Florian Weimer <fweimer redhat.com>]

Fixed at 45a6f8f2b3. Leaving open for SA.

comment:3 by Bruce Dubbs, 6 weeks ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-198 has been issued.

Note: See TracTickets for help on using tickets.