UbuntuUpdates.org

Package "libapr1"

Name: libapr1

Description:

Apache Portable Runtime Library

Latest version: 1.4.6-1
Release: precise (12.04)
Level: base
Repository: main
Head package: apr
Homepage: http://apr.apache.org/

Links


Download "libapr1"


Other versions of "libapr1" in Precise

No other version of this package is available in the Precise release.

Changelog

Version: 1.4.6-1 2012-03-20 15:06:51 UTC

apr (1.4.6-1) unstable; urgency=low

  * New upstream release:
    - Fixes apr_file_trunc() bug which could lead to subversion repository
      corruption. Closes: #664451
    - Adds randomization to hashes. CVE-2012-0840 (but not known to be
      exploitable in httpd or svn). Closes: #655435
  * Remove Tollef Fog Heen and Ryan Niebur from uploaders. Thanks for your
    work in the past.

 -- Stefan Fritsch Sun, 18 Mar 2012 23:22:59 +0100

Source diff to previous version
664451 apr: [PATCH] apr_file_trunc() bug causes svn repository corruption - Debian Bug report logs
655435 libapr1: apr_hash vulnerable to oCert-2011-003 style DOS attacks - Debian Bug report logs
CVE-2012-0840 tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash coll

Version: 1.4.5-1.1ubuntu2 2012-02-24 14:03:43 UTC

apr (1.4.5-1.1ubuntu2) precise; urgency=low

  * Revert the previous upload; apr_cv_mutex_robust_shared still
    hangs on our current buildd setup; need to revisit later.

 -- Adam Conrad Fri, 24 Feb 2012 04:51:20 -0700

Source diff to previous version

Version: 1.4.5-1.1ubuntu1 2012-02-24 09:03:15 UTC

apr (1.4.5-1.1ubuntu1) precise; urgency=low

  * debian/rules: Re-enable apr_cv_mutex_robust_shared support on
    armel and armhf. If the kernels on the builders are recent enough
    this closes: #604753 again.

 -- Jani Monoses Thu, 23 Feb 2012 23:29:01 +0200

604753 [eglibc] process shared mutex's fail on armel v7 (thumb)



About   -   Send Feedback to @ubuntu_updates