Source: apr-util
Version: 1.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for apr-util.
CVE-2025-49506[0]:
| APR-util versions 1.6.3 (and earlier) function
| apr_password_validate() was not constant-time with regards to hashes
| or passwords comparisons, potentially leaking their content via a
| side channel timing attack particularly on platforms without crypt()
| such as Windows, BeOS, NetWare, or Android. Users are recommended
| to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327[1]:
| A bug in APR-util version 1.6.3 (and earlier) allows a stack
| recursion attack against any library consumer which parses XML from
| untrusted sources and uses the apr_xml_quote_elem() function. Users
| are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-34191[2]:
| Improper Neutralization of Special Elements used in an SQL Command
| ('SQL Injection') vulnerability in Apache Portable Runtime Utility
| via apr_dbd_oracle provider. This issue affects Apache Portable
| Runtime Utility: from 1.6.0 through 1.6.3
CVE-2026-34501[3]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility redis client. This issue affects Apache Portable Runtime
| Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade
| to version 1.6.4, which fixes the issue.
CVE-2026-34502[4]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility memcached client This issue affects Apache Portable Runtime
| Utility: from 1.3.0 through 1.6.3.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-49506
https://www.cve.org/CVERecord?id=CVE-2025-49506
[1] https://security-tracker.debian.org/tracker/CVE-2026-32327
https://www.cve.org/CVERecord?id=CVE-2026-32327
[2] https://security-tracker.debian.org/tracker/CVE-2026-34191
https://www.cve.org/CVERecord?id=CVE-2026-34191
[3] https://security-tracker.debian.org/tracker/CVE-2026-34501
https://www.cve.org/CVERecord?id=CVE-2026-34501
[4] https://security-tracker.debian.org/tracker/CVE-2026-34502
https://www.cve.org/CVERecord?id=CVE-2026-34502
Regards,
Salvatore