Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Slackware 12.2: SSA:2009-167-02 Critical: apr-util Denial Of Service

slackware
Calendar Grey June 17, 2009
Dist Slackware Esm H88
Enhancement of the apr-util software in Slackware to mitigate vulnerabilities such as denial of service threats and implement necessary corrections.
New apr-util (and apr) packages are available for Slackware 11.0, 12.0, 12.1, 12.2, and -current to fix security issues

Summary

Here are the details from the Slackware 12.2 ChangeLog: patches/packages/apr-1.3.5-i486-1_slack12.2.tgz: Upgraded. patches/packages/apr-util-1.3.7-i486-1_slack12.2.tgz: Upgraded. Fix underflow in apr_strmatch_precompile. Fix a denial of service attack against the apr_xml_* interface using the "billion laughs" entity expansion technique. For more information, see: https://www.cve.org/CVERecord?id=CVE-2009-0023 https://www.cve.org/CVERecord?id=CVE-2009-1955 (* Security fix *)

Where Find New Packages

HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com.
Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated packages for Slackware 11.0:
Updated packages for Slackware 12.0:
Updated packages for Slackware 12.1:
Updated packages for Slackware 12.2:
Updated packages for Slackware -current:
Updated packages for Slackware64 -current:

MD5 Signatures

Slackware 11.0 packages: ac9c2bd1c832b3c0c6591e5093d22574 apr-1.3.5-i486-1_slack11.0.tgz 11c43b25594f4f80d2e9a57d2c5e7529 apr-util-1.3.7-i486-1_slack11.0.tgz
Slackware 12.0 packages: 7530bd4fabcfb8bfead159317deb1d9d apr-1.3.5-i486-1_slack12.0.tgz 920adee38b69d8ab622ae7e24f02b6f5 apr-util-1.3.7-i486-1_slack12.0.tgz
Slackware 12.1 packages: a37e104e2f1e7fe431fdfe8dd9f9419b apr-1.3.5-i486-1_slack12.1.tgz 74c0246803ed50eab16ef77bf65a2d6a apr-util-1.3.7-i486-1_slack12.1.tgz
Slackware 12.2 packages: e276ed3382240e432c10f36617713413 apr-1.3.5-i486-1_slack12.2.tgz 49fa603e108d01ade6314b9a1c436ef1 apr-util-1.3.7-i486-1_slack12.2.tgz
Slackware -current packages: 606c7f33edb9de39b1fd79aa3b87fe0a apr-1.3.5-i486-1.txz 453715fe39f01072d03a694ac3efd3f1 apr-util-1.3.7-i486-1.txz
Slackware64 -current packages: e461c38f40409b9116ba961a54da158b apr-1.3.5-x86_64-1.txz 4575a1349995790b06f7063fdd389f01 apr-util-1.3.7-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the packages as root: # upgradepkg apr-1.3.5-i486-1_slack12.2.tgz apr-util-1.3.7-i486-1_slack12.2.tgz Then restart any services that use apr-util.

Related News

Your message here