Thank you for your contribution to Debian.

Mapping stable-security to proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 09 Aug 2026 18:26:22 +0200
Source: apr-util
Architecture: source
Version: 1.6.3-3+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Apache Maintainers <[email protected]>
Changed-By: Bastien Roucariès <[email protected]>
Closes: 1143837
Changes:
 apr-util (1.6.3-3+deb13u1) trixie-security; urgency=high
 .
   * Non-maintainer upload on behalf of Apache Team.
     (Closes: #1143837)
   * Fix CVE-2025-49506:
     Function apr_password_validate() was not constant-time with
     regards to hashes or passwords comparisons, potentially leaking
     their content via a side channel timing attack.
   * Fix CVE-2026-32327:
     A stack recursion attack against any library consumer
     which parses XML from untrusted sources and uses the
     apr_xml_quote_elem() function
   * Fix CVE-2026-34191:
     Improper Neutralization of Special Elements used
     in an SQL Command (SQL Injection) vulnerability
     in Apache Portable Runtime Utility via apr_dbd_oracle provider.
   * Fix CVE-2026-34501:
     Heap-based Buffer Overflow vulnerability in Apache Portable
     Runtime Utility redis client.
   * Fix CVE-2026-34502:
     Heap-based Buffer Overflow vulnerability in Apache Portable
     Runtime Utility memcached client
Checksums-Sha1:
 f7e142cf8d4d3c02942e513807a2b2413026bfe6 2572 apr-util_1.6.3-3+deb13u1.dsc
 8c6293a787b69986ce43bc49c7c247d4ff5fc828 432692 apr-util_1.6.3.orig.tar.bz2
 bc1f492a7e1e2b1468c23285c1d86f62f0dcbf31 348040 
apr-util_1.6.3-3+deb13u1.debian.tar.xz
 ac6ca17ec03273650e02ed4a0960db0c368a5c32 5888 
apr-util_1.6.3-3+deb13u1_source.buildinfo
Checksums-Sha256:
 1b1bc45ea8927794f1901e75a5415fff11625815b34fc4c071df89710c61f6e0 2572 
apr-util_1.6.3-3+deb13u1.dsc
 a41076e3710746326c3945042994ad9a4fcac0ce0277dd8fea076fec3c9772b5 432692 
apr-util_1.6.3.orig.tar.bz2
 5bd2179a2cd4ac4351286a107431111b738b8f0d1c8fa65022bef34b72629278 348040 
apr-util_1.6.3-3+deb13u1.debian.tar.xz
 4a676e49089e9c4d8768acdd945e962eb649f4b0d5a2f318c7d7e165ada8694f 5888 
apr-util_1.6.3-3+deb13u1_source.buildinfo
Files:
 5a4d8090fe2552bf7c3f53d06cba1eeb 2572 libs optional 
apr-util_1.6.3-3+deb13u1.dsc
 b6e8c9b31d938fe5797ceb0d1ff2eb69 432692 libs optional 
apr-util_1.6.3.orig.tar.bz2
 6d9ca0ac73b3a8eb9d9fc9c47a061e20 348040 libs optional 
apr-util_1.6.3-3+deb13u1.debian.tar.xz
 99a0383372dd2ec153ee840df1387c65 5888 libs optional 
apr-util_1.6.3-3+deb13u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmp8fzIACgkQADoaLapB
CF9Eow/+MEHRdf3GNoP5hcp1rwcgmljmx3CLcNr5Rvkc9u8DJalB7fdu0SDVW6M/
KoayYJ1u3tzn6Ro0OYfmDnhDjIp59FA//2dkSGhHuhRYfpFdjGU6C0rGUaYzN1gW
Xl4nQnLFVWzMfuAuZLZSK1FJ5xp4tq+OrCHbOEd7bVv8iOPv9lN2iZBwLk1gouJG
OEBQvxREVxcoKyv3/RT6K5dO8lJoXwWnH3bkzCG11tSt2dWSksiABkc0v9Tg2x1c
vbZZ8oqn3WiDmA1f8cXQTGTXvjx3DGiyICGvjJm3mxYcXEGLFHaT7AOrXfKctCRt
JpefhxoVHyUf1jHDm0IBnoS31aGUy101gVnfYON9LEJPHraQRey9F7e1tB+p/a/T
mm/CzEizgH2cJmVo8G1Q3UfZ/xvE/ZUt3hojTT0rgBwy7bRrd8QbYra7A1+vkIfJ
EwJB1jJqYx/Kc5xU2pc3FakCJqoPx8cU6pI9qmdRGQNCZK87DhP9PYqJT8RM36T+
6/RkP+jcjpZa05vwG93DFmXJJOu0UwaayGZOcKwZcJQizebbL6b8ALY+9NB9urmy
Ne6+Oelt5QP/Xdee+nB4yM7b68ItONqcisY00uIUx/gAO98+gpp8PldI1oJ97PAM
WHLFtirzxSPMMO1ZW7DsVOeWfG+wZZb1cJTvopzUmXlPcGSHVGU=
=Lyar
-----END PGP SIGNATURE-----

Attachment: pgpLmbXUBP2yd.pgp
Description: PGP signature

Reply via email to