Your message dated Fri, 07 Aug 2026 15:06:33 +0000
with message-id <[email protected]>
and subject line Bug#1143837: fixed in apr-util 1.6.4-1
has caused the Debian Bug report #1143837,
regarding apr-util: CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34501
CVE-2026-34502
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143837: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143837
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: apr-util
Version: 1.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for apr-util.
CVE-2025-49506[0]:
| APR-util versions 1.6.3 (and earlier) function
| apr_password_validate() was not constant-time with regards to hashes
| or passwords comparisons, potentially leaking their content via a
| side channel timing attack particularly on platforms without crypt()
| such as Windows, BeOS, NetWare, or Android. Users are recommended
| to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327[1]:
| A bug in APR-util version 1.6.3 (and earlier) allows a stack
| recursion attack against any library consumer which parses XML from
| untrusted sources and uses the apr_xml_quote_elem() function. Users
| are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-34191[2]:
| Improper Neutralization of Special Elements used in an SQL Command
| ('SQL Injection') vulnerability in Apache Portable Runtime Utility
| via apr_dbd_oracle provider. This issue affects Apache Portable
| Runtime Utility: from 1.6.0 through 1.6.3
CVE-2026-34501[3]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility redis client. This issue affects Apache Portable Runtime
| Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade
| to version 1.6.4, which fixes the issue.
CVE-2026-34502[4]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility memcached client This issue affects Apache Portable Runtime
| Utility: from 1.3.0 through 1.6.3.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-49506
https://www.cve.org/CVERecord?id=CVE-2025-49506
[1] https://security-tracker.debian.org/tracker/CVE-2026-32327
https://www.cve.org/CVERecord?id=CVE-2026-32327
[2] https://security-tracker.debian.org/tracker/CVE-2026-34191
https://www.cve.org/CVERecord?id=CVE-2026-34191
[3] https://security-tracker.debian.org/tracker/CVE-2026-34501
https://www.cve.org/CVERecord?id=CVE-2026-34501
[4] https://security-tracker.debian.org/tracker/CVE-2026-34502
https://www.cve.org/CVERecord?id=CVE-2026-34502
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: apr-util
Source-Version: 1.6.4-1
Done: Stefan Fritsch <[email protected]>
We believe that the bug you reported is fixed in the latest version of
apr-util, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Stefan Fritsch <[email protected]> (supplier of updated apr-util package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 07 Aug 2026 16:47:11 +0200
Source: apr-util
Architecture: source
Version: 1.6.4-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Apache Maintainers <[email protected]>
Changed-By: Stefan Fritsch <[email protected]>
Closes: 1137309 1143837
Changes:
apr-util (1.6.4-1) unstable; urgency=medium
.
* New upstream release. Closes: #1143837
- CVE-2025-49506: apr_password_validate() vulnerable to timing attack
- CVE-2026-32327: XML stack recursion crash
- CVE-2026-34191: SQL Injection in apr_dbd_oracle
- CVE-2026-34501: Heap buffer overflow in APR redis client
- CVE-2026-34502: Heap buffer overflow in APR memcached client
* Switch Build-Depends to libmariadb-dev-compat. Closes: #1137309
Checksums-Sha1:
05cf8eed3049bbc4064b19469f89b500fde25a33 2785 apr-util_1.6.4-1.dsc
913c44f9fdfb4ce7c270a71a52402d33adcd99b6 441511 apr-util_1.6.4.orig.tar.bz2
0f6ce32a62a43287583020980f4ee92863a6ddd9 898 apr-util_1.6.4.orig.tar.bz2.asc
628aff0f2656a2445f534e90e3bc4c83efd96be8 341248 apr-util_1.6.4-1.debian.tar.xz
7cc98e36a29cf49fc43ebf63d87cf883bdf590fc 8868 apr-util_1.6.4-1_source.buildinfo
Checksums-Sha256:
1949bd1da9929e3fa89e7dc3228a9ff229ef4e051859e08c4276088a27a5ebe0 2785
apr-util_1.6.4-1.dsc
3e2ae08f40efa0c3701e54a954cefa08242de22a69f91a8ae44fc1e624ba309b 441511
apr-util_1.6.4.orig.tar.bz2
17eb58050f65c3889195f3077e36521a9af3e36b100efef690f50916c3116bf8 898
apr-util_1.6.4.orig.tar.bz2.asc
c7b5d7f28207a71d2da66097c0cec9f5c16d8df5a4e2749668de9bd9387b2c52 341248
apr-util_1.6.4-1.debian.tar.xz
ae3cad3210b39b1d6decc8ba3dcbeb87cebdfeb8b007aa4302b705331f615a78 8868
apr-util_1.6.4-1_source.buildinfo
Files:
6ed9c453a7b2fac39ceaf4b52f75e18c 2785 libs optional apr-util_1.6.4-1.dsc
8c933056e21005f69225ec6ffd0a16d3 441511 libs optional
apr-util_1.6.4.orig.tar.bz2
97e710b9cfafb504e05535cd333ac2b6 898 libs optional
apr-util_1.6.4.orig.tar.bz2.asc
77fe06bcd2cc04a3e31f6a2865a9b304 341248 libs optional
apr-util_1.6.4-1.debian.tar.xz
f0636d01caa704fced3bce64f3549a48 8868 libs optional
apr-util_1.6.4-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEOpiNza8JqByyYYsxxodfNUHO/eAFAmp18PAACgkQxodfNUHO
/eBhtw/+MlsN3Ims0oKb/8dh+6wpC2OVgsHVfZ+3Fh/HIyhBWPtXKjTKVs4qsgpH
/oaM2YoFmNg9u18ZuK3tPbso9ZVyBLod/hjhdBf2bY9v1rSa6FmF1rugKMuGFPid
JqBgHkUqV2BbgTsuUNsgzzDq1jA0n+WMeD6ZNbuYz1IavoaU1p8GkoTAECGdayVf
Qvvt5aP1jJK7uortJY8+qQ+KghcoNCnNa6BHewmF9U9j1GnBcn5bMuhIc1fh1x0D
jKoKiu+Pba7AlwwCy7pKM+YGPrFgkUrL1LsWt7VPqB2HhA7LdUAng0+qfOk+4lWJ
qdgcBPh8EZ0RZZWNGJMjsr7W5GMW4iNHnNmoNqw2zO1E9610R9dfs/kENqkv5yg9
Qt0lv7zGdD29e6epY87pUN/UQxHOlOUsMUuobMxqJ3qhmtE5NKidr7i6fXAR2qUc
lh+AT7EqhUCqu7Z1ztSdDaChfK7EDNTnh+vGRApjo4Mgy02dTRjv++RRsNfqvyYN
wL9ceJmTCxH4e5PaBGtTSlC6lz0B6+Cpzzz19E4N0LZ2zMEEuyvhIJYe2UMIgE7N
rqZbKzkVDrAAe4/EW1Y6pE6HAkl8OCC4DzU5Bum2QaKb8+ozsTYT6rTl00AL9ftG
L6wV3FVm6ZVavnT5kfdFFrox+iXsBZnONqA2KluS3u+SL+HqZXA=
=tihJ
-----END PGP SIGNATURE-----
pgpulAeDNunlc.pgp
Description: PGP signature
--- End Message ---