Описание
Security update for apr-util
This update for apr-util fixes the following issues:
- CVE-2025-49506: hash/password content leak via side channel timing attack against
apr_password_validate()(bsc#1274237). - CVE-2026-32327: XML stack recursion crash (bsc#1274235).
- CVE-2026-34191: SQL injection via
apr_dbd_oracle(bsc#1274850). - CVE-2026-34501: heap buffer overflow in redis client (bsc#1274852).
- CVE-2026-34502: heap buffer overflow in APR memcached client (bsc#1274854).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1274235
- SUSE Bug 1274237
- SUSE Bug 1274850
- SUSE Bug 1274852
- SUSE Bug 1274854
- SUSE CVE CVE-2025-49506 page
- SUSE CVE CVE-2026-32327 page
- SUSE CVE CVE-2026-34191 page
- SUSE CVE CVE-2026-34501 page
- SUSE CVE CVE-2026-34502 page
Описание
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Затронутые продукты
Ссылки
- CVE-2025-49506
- SUSE Bug 1274237
Описание
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Затронутые продукты
Ссылки
- CVE-2026-32327
- SUSE Bug 1274235
Описание
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
Затронутые продукты
Ссылки
- CVE-2026-34191
- SUSE Bug 1274850
Описание
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
Затронутые продукты
Ссылки
- CVE-2026-34501
- SUSE Bug 1274852
Описание
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
Затронутые продукты
Ссылки
- CVE-2026-34502
- SUSE Bug 1274854