Logo
componentapr-util
Name
apr-util
Version
1.6.3-r1
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:apache:apr-util:1.6.3:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
1.6.3-r1

Patches#


#
Title
Author
Resolve
1
Prevent recursive linking of dependent libraries by apr-util users.
Peter Samuelson <peter@p12n.org>
2
by default --avoid-ldap since apache2 is the only user, and we don't
Ryan Niebur <ryanryan52@gmail.com>
3
Make apu-config not output dbm libs by default. See #622081
Stefan Fritsch <sf@debian.org>

Vulnerabilities#


Name
Analysis
Description
Exploitable
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
Exploitable
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
Exploitable
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
Exploitable
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Exploitable
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.