Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-49506

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

A flaw was found in Apache Portable Runtime Utility (apr-util). The apr_password_validate() function does not perform constant-time comparisons for hashes or passwords. This vulnerability allows a remote attacker to conduct a timing attack, particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. By observing the time differences in comparisons, an attacker could potentially deduce the content of sensitive information like password hashes.

Отчет

This vulnerability is assessed as Low Impact due to significant practical exploitation barriers. While the theoretical outcome of a successful timing attack is hash disclosure (Confidentiality: High), isolating microsecond-level comparison differences over a network is rendered practically infeasible by unpredictable network latency, packet jitter, and server scheduling noise (Attack Complexity: High). Additionally, RHEL environments natively rely on the system crypt() implementation for standard password checks, bypassing the vulnerable non-constant-time fallback code path in standard deployment scenarios.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10apr-utilFix deferred
Red Hat Enterprise Linux 6apr-utilOut of support scope
Red Hat Enterprise Linux 7apr-utilFix deferred
Red Hat Enterprise Linux 8apr-utilFix deferred
Red Hat Enterprise Linux 9apr-utilFix deferred
Red Hat Hardened Imagesapr-utilAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2512077apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation

EPSS

Процентиль: 33%
0.00394
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 7.5
nvd
11 дней назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

msrc
8 дней назад

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack

CVSS3: 7.5
debian
11 дней назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() ...

CVSS3: 7.5
github
11 дней назад

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

EPSS

Процентиль: 33%
0.00394
Низкий

5.9 Medium

CVSS3