Количество 32
Количество 32
RLSA-2026:66392
Moderate: apr-util security update
RLSA-2026:66341
Moderate: apr-util security update
ELSA-2026-66392-0
ELSA-2026-66392-0: apr-util security update (MODERATE)
ELSA-2026-66341-0
ELSA-2026-66341-0: apr-util security update (MODERATE)
openSUSE-SU-2026:21672-1
Security update for apr-util
SUSE-SU-2026:3938-1
Security update for apr-util
SUSE-SU-2026:3937-1
Security update for apr-util
SUSE-SU-2026:3905-1
Security update for libapr-util1
CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2025-49506
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() ...
GHSA-73wm-47mq-62r5
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327
Apache Portable Runtime Utility: apr-util XML stack recursion crash
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ...
GHSA-qfxp-vc85-jg39
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:66392 Moderate: apr-util security update | 10 дней назад | |||
RLSA-2026:66341 Moderate: apr-util security update | 10 дней назад | |||
ELSA-2026-66392-0 ELSA-2026-66392-0: apr-util security update (MODERATE) | 12 дней назад | |||
ELSA-2026-66341-0 ELSA-2026-66341-0: apr-util security update (MODERATE) | 12 дней назад | |||
openSUSE-SU-2026:21672-1 Security update for apr-util | 25 дней назад | |||
SUSE-SU-2026:3938-1 Security update for apr-util | 19 дней назад | |||
SUSE-SU-2026:3937-1 Security update for apr-util | 19 дней назад | |||
SUSE-SU-2026:3905-1 Security update for libapr-util1 | 21 день назад | |||
CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | CVSS3: 5.9 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() ... | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-73wm-47mq-62r5 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | CVSS3: 9.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | CVSS3: 6.2 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | CVSS3: 9.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-32327 Apache Portable Runtime Utility: apr-util XML stack recursion crash | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ... | CVSS3: 9.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-qfxp-vc85-jg39 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | CVSS3: 9.1 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу