UbuntuUpdates.org

Package "apr-util"

Name: apr-util

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Apache Portable Runtime Utility Library - MySQL Driver
  • Apache Portable Runtime Utility Library - ODBC Driver
  • Apache Portable Runtime Utility Library - PostgreSQL Driver

Latest version: 1.6.3-1.1ubuntu7.1
Release: noble (24.04)
Level: security
Repository: universe

Links



Other versions of "apr-util" in Noble

Repository Area Version
base universe 1.6.3-1.1ubuntu7
base main 1.6.3-1.1ubuntu7
security main 1.6.3-1.1ubuntu7.1
updates main 1.6.3-1.1ubuntu7.1
updates universe 1.6.3-1.1ubuntu7.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.6.3-1.1ubuntu7.1 2026-09-03 13:07:41 UTC

apr-util (1.6.3-1.1ubuntu7.1) noble-security; urgency=medium

  * SECURITY UPDATE: Timing side-channel attack
    - debian/patches/CVE-2025-49506.patch: Merge r1936804 from aprutil 1.7.x:
    - CVE-2025-49506
  * SECURITY UPDATE: Improper input validation
    - debian/patches/CVE-2026-32327_pre1.patch: Merge r1914772 from 1.7.x:
    - debian/patches/CVE-2026-32327.patch: Merge r1936807 from 1.7.x:
    - CVE-2026-32327
  * SECURITY UPDATE: Improper input validation
    - debian/patches/CVE-2026-34501.patch: Merge r1936809 from aprutil 1.7.x:
    - CVE-2026-34501
  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2026-34502.patch: Merge r1936812 from aprutil 1.7.x:
    - CVE-2026-34502

 -- John Breton Wed, 02 Sep 2026 06:54:24 -0400

CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potenti
CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an
CVE-2026-34501 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1
CVE-2026-34502 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: fro



About   -   Send Feedback to @ubuntu_updates