UbuntuUpdates.org

Package "libaprutil1-dbd-pgsql"

Name: libaprutil1-dbd-pgsql

Description:

Apache Portable Runtime Utility Library - PostgreSQL Driver

Latest version: 1.6.1-5ubuntu4.22.04.3
Release: jammy (22.04)
Level: security
Repository: universe
Head package: apr-util
Homepage: http://apr.apache.org/

Links


Download "libaprutil1-dbd-pgsql"


Other versions of "libaprutil1-dbd-pgsql" in Jammy

Repository Area Version
base universe 1.6.1-5ubuntu4
updates universe 1.6.1-5ubuntu4.22.04.3

Changelog

Version: 1.6.1-5ubuntu4.22.04.3 2026-09-03 13:07:39 UTC

apr-util (1.6.1-5ubuntu4.22.04.3) jammy-security; urgency=medium

  * SECURITY UPDATE: Timing side-channel attack
    - debian/patches/CVE-2025-49506.patch: Merge r1936804 from aprutil 1.7.x:
    - CVE-2025-49506
  * SECURITY UPDATE: Improper input validation
    - debian/patches/CVE-2026-32327_pre1.patch: Merge r1914772 from 1.7.x:
    - debian/patches/CVE-2026-32327.patch: Merge r1936807 from 1.7.x:
    - CVE-2026-32327
  * SECURITY UPDATE: Improper input validation
    - debian/patches/CVE-2026-34501.patch: Merge r1936809 from aprutil 1.7.x:
    - CVE-2026-34501
  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2026-34502.patch: Merge r1936812 from aprutil 1.7.x:
    - CVE-2026-34502

 -- John Breton Wed, 02 Sep 2026 06:57:12 -0400

Source diff to previous version
CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potenti
CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an
CVE-2026-34501 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1
CVE-2026-34502 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: fro

Version: 1.6.1-5ubuntu4.22.04.2 2023-09-04 12:08:05 UTC

  apr-util (1.6.1-5ubuntu4.22.04.2) jammy-security; urgency=medium

  * Fix compatibility with MySQL 8.0.34 (LP: #2031548)
    - debian/patches/fix-mysql-8034-compat.patch: don't set
      MYSQL_OPT_RECONNECT as it is deprecated and spews and error message.

 -- Leonidas Da Silva Barbosa <email address hidden> Thu, 31 Aug 2023 11:24:22 -0300

Source diff to previous version

Version: 1.6.1-5ubuntu4.22.04.1 2023-02-14 22:07:22 UTC

  apr-util (1.6.1-5ubuntu4.22.04.1) jammy-security; urgency=medium

  * SECURITY UPDATE: integer overflow
     - debian/patches/CVE-2022-25147.patch: add assertions to check if
       a buffer length is bigger than a pre-determined value in
       multiple methods in encoding/apr_base64.c.
     - CVE-2022-25147

 -- Rodrigo Figueiredo Zaiden <email address hidden> Mon, 13 Feb 2023 12:37:29 -0300

CVE-2022-25147 Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond



About   -   Send Feedback to @ubuntu_updates