This bug was fixed in the package apr-util - 1.6.4-2ubuntu1
---------------
apr-util (1.6.4-2ubuntu1) stonking; urgency=medium
* Merge with Debian unstable (LP: #2166174). Remaining changes:
- dbd/apr_dbd_mysql.c: Update MySQL backend for MySQL 8 compatibility
- d/control: Keep using libmysqlclient-dev in Ubuntu instead of
libmariadb-dev-compat
* Remove remaining ENGINE references for OpenSSL 4 compat (LP: #2165311)
- d/p/Remove_remaining_ENGINE_references.patch
apr-util (1.6.4-2) unstable; urgency=medium
* Re-upload fixed source. The 1.6.3-4 changes were missing in
1.6.4-1.
apr-util (1.6.4-1) unstable; urgency=medium
* New upstream release. Closes: #1143837
- CVE-2025-49506: apr_password_validate() vulnerable to timing attack
- CVE-2026-32327: XML stack recursion crash
- CVE-2026-34191: SQL Injection in apr_dbd_oracle
- CVE-2026-34501: Heap buffer overflow in APR redis client
- CVE-2026-34502: Heap buffer overflow in APR memcached client
* Switch Build-Depends to libmariadb-dev-compat. Closes: #1137309
-- Ravi Kant Sharma <[email protected]> Wed, 02 Sep 2026
13:17:12 +0200
** Changed in: apr-util (Ubuntu)
Status: New => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2025-49506
** CVE added: https://cve.org/CVERecord?id=CVE-2026-32327
** CVE added: https://cve.org/CVERecord?id=CVE-2026-34191
** CVE added: https://cve.org/CVERecord?id=CVE-2026-34501
** CVE added: https://cve.org/CVERecord?id=CVE-2026-34502
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2165311
Title:
FTBFS: subversion fails to build with OpenSSL 4 and apr-utils < 1.6.4
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apr-util/+bug/2165311/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs