Your message dated Tue, 18 Aug 2026 21:47:06 +0000
with message-id <[email protected]>
and subject line Bug#1143837: fixed in apr-util 1.6.3-3+deb13u1
has caused the Debian Bug report #1143837,
regarding apr-util: CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34501
CVE-2026-34502
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143837: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143837
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: apr-util
Version: 1.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for apr-util.
CVE-2025-49506[0]:
| APR-util versions 1.6.3 (and earlier) function
| apr_password_validate() was not constant-time with regards to hashes
| or passwords comparisons, potentially leaking their content via a
| side channel timing attack particularly on platforms without crypt()
| such as Windows, BeOS, NetWare, or Android. Users are recommended
| to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327[1]:
| A bug in APR-util version 1.6.3 (and earlier) allows a stack
| recursion attack against any library consumer which parses XML from
| untrusted sources and uses the apr_xml_quote_elem() function. Users
| are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-34191[2]:
| Improper Neutralization of Special Elements used in an SQL Command
| ('SQL Injection') vulnerability in Apache Portable Runtime Utility
| via apr_dbd_oracle provider. This issue affects Apache Portable
| Runtime Utility: from 1.6.0 through 1.6.3
CVE-2026-34501[3]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility redis client. This issue affects Apache Portable Runtime
| Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade
| to version 1.6.4, which fixes the issue.
CVE-2026-34502[4]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility memcached client This issue affects Apache Portable Runtime
| Utility: from 1.3.0 through 1.6.3.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-49506
https://www.cve.org/CVERecord?id=CVE-2025-49506
[1] https://security-tracker.debian.org/tracker/CVE-2026-32327
https://www.cve.org/CVERecord?id=CVE-2026-32327
[2] https://security-tracker.debian.org/tracker/CVE-2026-34191
https://www.cve.org/CVERecord?id=CVE-2026-34191
[3] https://security-tracker.debian.org/tracker/CVE-2026-34501
https://www.cve.org/CVERecord?id=CVE-2026-34501
[4] https://security-tracker.debian.org/tracker/CVE-2026-34502
https://www.cve.org/CVERecord?id=CVE-2026-34502
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: apr-util
Source-Version: 1.6.3-3+deb13u1
Done: Bastien Roucariès <[email protected]>
We believe that the bug you reported is fixed in the latest version of
apr-util, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Bastien Roucariès <[email protected]> (supplier of updated apr-util package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 09 Aug 2026 18:26:22 +0200
Source: apr-util
Architecture: source
Version: 1.6.3-3+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Apache Maintainers <[email protected]>
Changed-By: Bastien Roucariès <[email protected]>
Closes: 1143837
Changes:
apr-util (1.6.3-3+deb13u1) trixie-security; urgency=high
.
* Non-maintainer upload on behalf of Apache Team.
(Closes: #1143837)
* Fix CVE-2025-49506:
Function apr_password_validate() was not constant-time with
regards to hashes or passwords comparisons, potentially leaking
their content via a side channel timing attack.
* Fix CVE-2026-32327:
A stack recursion attack against any library consumer
which parses XML from untrusted sources and uses the
apr_xml_quote_elem() function
* Fix CVE-2026-34191:
Improper Neutralization of Special Elements used
in an SQL Command (SQL Injection) vulnerability
in Apache Portable Runtime Utility via apr_dbd_oracle provider.
* Fix CVE-2026-34501:
Heap-based Buffer Overflow vulnerability in Apache Portable
Runtime Utility redis client.
* Fix CVE-2026-34502:
Heap-based Buffer Overflow vulnerability in Apache Portable
Runtime Utility memcached client
Checksums-Sha1:
f7e142cf8d4d3c02942e513807a2b2413026bfe6 2572 apr-util_1.6.3-3+deb13u1.dsc
8c6293a787b69986ce43bc49c7c247d4ff5fc828 432692 apr-util_1.6.3.orig.tar.bz2
bc1f492a7e1e2b1468c23285c1d86f62f0dcbf31 348040
apr-util_1.6.3-3+deb13u1.debian.tar.xz
ac6ca17ec03273650e02ed4a0960db0c368a5c32 5888
apr-util_1.6.3-3+deb13u1_source.buildinfo
Checksums-Sha256:
1b1bc45ea8927794f1901e75a5415fff11625815b34fc4c071df89710c61f6e0 2572
apr-util_1.6.3-3+deb13u1.dsc
a41076e3710746326c3945042994ad9a4fcac0ce0277dd8fea076fec3c9772b5 432692
apr-util_1.6.3.orig.tar.bz2
5bd2179a2cd4ac4351286a107431111b738b8f0d1c8fa65022bef34b72629278 348040
apr-util_1.6.3-3+deb13u1.debian.tar.xz
4a676e49089e9c4d8768acdd945e962eb649f4b0d5a2f318c7d7e165ada8694f 5888
apr-util_1.6.3-3+deb13u1_source.buildinfo
Files:
5a4d8090fe2552bf7c3f53d06cba1eeb 2572 libs optional
apr-util_1.6.3-3+deb13u1.dsc
b6e8c9b31d938fe5797ceb0d1ff2eb69 432692 libs optional
apr-util_1.6.3.orig.tar.bz2
6d9ca0ac73b3a8eb9d9fc9c47a061e20 348040 libs optional
apr-util_1.6.3-3+deb13u1.debian.tar.xz
99a0383372dd2ec153ee840df1387c65 5888 libs optional
apr-util_1.6.3-3+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmp8fzIACgkQADoaLapB
CF9Eow/+MEHRdf3GNoP5hcp1rwcgmljmx3CLcNr5Rvkc9u8DJalB7fdu0SDVW6M/
KoayYJ1u3tzn6Ro0OYfmDnhDjIp59FA//2dkSGhHuhRYfpFdjGU6C0rGUaYzN1gW
Xl4nQnLFVWzMfuAuZLZSK1FJ5xp4tq+OrCHbOEd7bVv8iOPv9lN2iZBwLk1gouJG
OEBQvxREVxcoKyv3/RT6K5dO8lJoXwWnH3bkzCG11tSt2dWSksiABkc0v9Tg2x1c
vbZZ8oqn3WiDmA1f8cXQTGTXvjx3DGiyICGvjJm3mxYcXEGLFHaT7AOrXfKctCRt
JpefhxoVHyUf1jHDm0IBnoS31aGUy101gVnfYON9LEJPHraQRey9F7e1tB+p/a/T
mm/CzEizgH2cJmVo8G1Q3UfZ/xvE/ZUt3hojTT0rgBwy7bRrd8QbYra7A1+vkIfJ
EwJB1jJqYx/Kc5xU2pc3FakCJqoPx8cU6pI9qmdRGQNCZK87DhP9PYqJT8RM36T+
6/RkP+jcjpZa05vwG93DFmXJJOu0UwaayGZOcKwZcJQizebbL6b8ALY+9NB9urmy
Ne6+Oelt5QP/Xdee+nB4yM7b68ItONqcisY00uIUx/gAO98+gpp8PldI1oJ97PAM
WHLFtirzxSPMMO1ZW7DsVOeWfG+wZZb1cJTvopzUmXlPcGSHVGU=
=Lyar
-----END PGP SIGNATURE-----
pgpGGmGUqkicJ.pgp
Description: PGP signature
--- End Message ---