UbuntuUpdates.org

Package "libaprutil1-dev"

Name: libaprutil1-dev

Description:

Apache Portable Runtime Utility Library - Development Headers

Latest version: 1.6.3-3ubuntu3.1
Release: resolute (26.04)
Level: updates
Repository: main
Head package: apr-util
Homepage: https://apr.apache.org/

Links


Download "libaprutil1-dev"


Other versions of "libaprutil1-dev" in Resolute

Repository Area Version
base main 1.6.3-3ubuntu3
security main 1.6.3-3ubuntu3.1

Changelog

Version: 1.6.3-3ubuntu3.1 2026-09-03 15:07:46 UTC

apr-util (1.6.3-3ubuntu3.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Timing side-channel attack
    - debian/patches/CVE-2025-49506.patch: Merge r1936804 from aprutil 1.7.x:
    - CVE-2025-49506
  * SECURITY UPDATE: Improper input validation
    - debian/patches/CVE-2026-32327_pre1.patch: Merge r1914772 from 1.7.x:
    - debian/patches/CVE-2026-32327.patch: Merge r1936807 from 1.7.x:
    - CVE-2026-32327
  * SECURITY UPDATE: Improper input validation
    - debian/patches/CVE-2026-34501.patch: Merge r1936809 from aprutil 1.7.x:
    - CVE-2026-34501
  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2026-34502.patch: Merge r1936812 from aprutil 1.7.x:
    - CVE-2026-34502

 -- John Breton Wed, 02 Sep 2026 06:51:50 -0400

CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potenti
CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an
CVE-2026-34501 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1
CVE-2026-34502 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: fro



About   -   Send Feedback to @ubuntu_updates