This bug was fixed in the package apr-util - 1.6.4-2ubuntu1

---------------
apr-util (1.6.4-2ubuntu1) stonking; urgency=medium

  * Merge with Debian unstable (LP: #2166174). Remaining changes:
    - dbd/apr_dbd_mysql.c: Update MySQL backend for MySQL 8 compatibility
    - d/control: Keep using libmysqlclient-dev in Ubuntu instead of
      libmariadb-dev-compat
  * Remove remaining ENGINE references for OpenSSL 4 compat (LP: #2165311)
    - d/p/Remove_remaining_ENGINE_references.patch

apr-util (1.6.4-2) unstable; urgency=medium

  * Re-upload fixed source. The 1.6.3-4 changes were missing in
    1.6.4-1.

apr-util (1.6.4-1) unstable; urgency=medium

  * New upstream release. Closes: #1143837
    - CVE-2025-49506: apr_password_validate() vulnerable to timing attack
    - CVE-2026-32327: XML stack recursion crash
    - CVE-2026-34191: SQL Injection in apr_dbd_oracle
    - CVE-2026-34501: Heap buffer overflow in APR redis client
    - CVE-2026-34502: Heap buffer overflow in APR memcached client
  * Switch Build-Depends to libmariadb-dev-compat. Closes: #1137309

 -- Ravi Kant Sharma <[email protected]>  Wed, 02 Sep 2026
13:17:12 +0200

** Changed in: apr-util (Ubuntu)
       Status: New => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2025-49506

** CVE added: https://cve.org/CVERecord?id=CVE-2026-32327

** CVE added: https://cve.org/CVERecord?id=CVE-2026-34191

** CVE added: https://cve.org/CVERecord?id=CVE-2026-34501

** CVE added: https://cve.org/CVERecord?id=CVE-2026-34502

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2165311

Title:
  FTBFS: subversion fails to build with OpenSSL 4 and apr-utils < 1.6.4

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apr-util/+bug/2165311/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to