Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-49506

Опубликовано: 06 авг. 2026
Источник: debian
EPSS Низкий

Описание

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apr-utilfixed1.6.4-1package

Примечания

  • https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5

  • Fixed by: https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e (1.6.4-rc1-candidate)

EPSS

Процентиль: 33%
0.00394
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 5.9
redhat
11 дней назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 7.5
nvd
11 дней назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

msrc
8 дней назад

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack

CVSS3: 7.5
github
11 дней назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

EPSS

Процентиль: 33%
0.00394
Низкий