The system could be made to expose sensitive information.. ========================================================================== Ubuntu Security Notice USN-7038-1 September 26, 2024 apr vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: The system could be made to expose sensitive information. Software Description: - apr: Apache Portable Runtime Library Details: Thomas Stangner discovered a permission vulnerability in the Apache Portable Runtime (APR) library. A local attacker could possibly use this issue to read named shared memory segments, potentially exposing sensitive application data. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libapr1-dev 1.7.2-3.1ubuntu0.1 libapr1t64 1.7.2-3.1ubuntu0.1 Ubuntu 22.04 LTS libapr1 1.7.0-8ubuntu0.22.04.2 libapr1-dev 1.7.0-8ubuntu0.22.04.2 Ubuntu 20.04 LTS libapr1 1.6.5-1ubuntu1.1 libapr1-dev 1.6.5-1ubuntu1.1 Ubuntu 18.04 LTS libapr1 1.6.3-2ubuntu0.1~esm1 Available with Ubuntu Pro libapr1-dev 1.6.3-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libapr1 1.5.2-3ubuntu0.1~esm2 Available with Ubuntu Pro libapr1-dev 1.5.2-3ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7038-1 CVE-2023-49582 Package Information: https://launchpad.net/ubuntu/+source/apr/1.7.2-3.1ubuntu0.1 https://launchpad.net/ubuntu/+source/apr/1.7.0-8ubuntu0.22.04.2 https://launchpad.net/ubuntu/+source/apr/1.6.5-1ubuntu1.1 . A vulnerability in the Apache Portable Runtime poses a risk of leaking sensitive data in Ubuntu platforms, as highlighted in this advisory notice.. Apache Portable Runtime, Ubuntu Security Advisory, Information Exposure, Local Attack, Permission Issue. . Severity: Critical. LinuxSecurity.com Team
* bsc#1229783 Cross-References: * CVE-2023-49582 . # Security update for apr Announcement ID: SUSE-SU-2024:3428-1 Rating: moderate References: * bsc#1229783 Cross-References: * CVE-2023-49582 CVSS scores: * CVE-2023-49582 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2023-49582 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2023-49582 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP5 * Basesystem Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for apr fixes the following issues: * CVE-2023-49582: Fixed an unexpected lax shared memory permissions. (bsc#1229783) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-3428=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3428=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3428=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-3428=1 ## Package List: * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libapr1-1.6.3-150000.3.6.1 * libapr1-debuginfo-1.6.3-150000.3.6.1 * apr-debugsource-1.6.3-150000.3.6.1 *apr-devel-1.6.3-150000.3.6.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libapr1-1.6.3-150000.3.6.1 * libapr1-debuginfo-1.6.3-150000.3.6.1 * apr-debugsource-1.6.3-150000.3.6.1 * apr-devel-1.6.3-150000.3.6.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libapr1-1.6.3-150000.3.6.1 * libapr1-debuginfo-1.6.3-150000.3.6.1 * apr-debugsource-1.6.3-150000.3.6.1 * apr-devel-1.6.3-150000.3.6.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libapr1-1.6.3-150000.3.6.1 * libapr1-debuginfo-1.6.3-150000.3.6.1 * apr-debugsource-1.6.3-150000.3.6.1 * apr-devel-1.6.3-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-49582.html * https://bugzilla.suse.com/show_bug.cgi?id=1229783 . Follow these installation guidelines to apply the latest SUSE APR security patch, addressing vulnerabilities across various distributions for enhanced safety. SUSE Security Update, apr Security Advisory, openSUSE Patch, Shared Memory Permissions Fix. . LinuxSecurity.com Team
* bsc#1229783 Cross-References: * CVE-2023-49582 . # Security update for apr Announcement ID: SUSE-SU-2024:3429-1 Rating: moderate References: * bsc#1229783 Cross-References: * CVE-2023-49582 CVSS scores: * CVE-2023-49582 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2023-49582 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2023-49582 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for apr fixes the following issues: * CVE-2023-49582: Fixed an unexpected lax shared memory permissions. (bsc#1229783) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-3429=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3429=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3429=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3429=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libapr1-devel-1.5.1-4.8.1 * libapr1-debuginfo-1.5.1-4.8.1 * libapr1-debugsource-1.5.1-4.8.1 * libapr1-1.5.1-4.8.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * libapr1-debuginfo-1.5.1-4.8.1 * libapr1-debugsource-1.5.1-4.8.1 * libapr1-1.5.1-4.8.1 *SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * libapr1-debuginfo-1.5.1-4.8.1 * libapr1-debugsource-1.5.1-4.8.1 * libapr1-1.5.1-4.8.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * libapr1-debuginfo-1.5.1-4.8.1 * libapr1-debugsource-1.5.1-4.8.1 * libapr1-1.5.1-4.8.1 ## References: * https://www.suse.com/security/cve/CVE-2023-49582.html * https://bugzilla.suse.com/show_bug.cgi?id=1229783 . A recent update for APR addresses CVE-2023-49581, which resolves insufficient validation of shared memory permissions, earning a moderate severity classification.. SUSE Linux, apr Security, memory permissions fix, Software updates, SUSE patches. . LinuxSecurity.com Team
Update APR to version 1.7.5.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-f831fe4030 2024-09-13 20:43:08.470423 -------------------------------------------------------------------------------- Name : apr Product : Fedora 41 Version : 1.7.5 Release : 1.fc41 URL : https://apr.apache.org/ Summary : Apache Portable Runtime library Description : The mission of the Apache Portable Runtime (APR) is to provide a free library of C data structures and routines, forming a system portability layer to as many operating systems as possible, including Unices, MS Win32, BeOS and OS/2. -------------------------------------------------------------------------------- Update Information: Update APR to version 1.7.5. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 28 2024 Joe Orton - 1.7.5-1 - update to 1.7.5 (#2307902) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2307902 - apr-1.7.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2307902 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f831fe4030' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Ronald Crane discovered that missing input saniting in the apr_encode functions of apr, the Apache Portable Runtime library, may result in denial of service or potentially the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5370-1
APR could possibly be made to crash or run programs if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-5885-1 February 27, 2023 apr vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS Summary: APR could possibly be made to crash or run programs if it received specially crafted network traffic. Software Description: - apr: Apache Portable Runtime Library Details: Ronald Crane discovered integer overflow vulnerabilities in the Apache Portable Runtime (APR) that could potentially result in memory corruption. A remote attacker could possibly use these issues to cause a denial of service or execute arbitary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: libapr1 1.7.0-8ubuntu0.22.10.1 Ubuntu 22.04 LTS: libapr1 1.7.0-8ubuntu0.22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5885-1 CVE-2022-24963 Package Information: https://launchpad.net/ubuntu/+source/apr/1.7.0-8ubuntu0.22.10.1 https://launchpad.net/ubuntu/+source/apr/1.7.0-8ubuntu0.22.04.1 . Ubuntu Security Notice USN-5886-1 addresses a security flaw in the OpenSSL library that exposes users to data breaches and unauthorized information access.. APR Vulnerability, Denial Of Service, Memory Corruption, Network Threat. . LinuxSecurity.com Team
An issue has been found in apr, the Apache Portable Runtime Library. The issue is related to out of bounds memory access due to invalid date fields. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2897-1
APR could be made to expose sensitive information if it received a specially crafted input.. =========================================================================Ubuntu Security Notice USN-5056-1 August 30, 2021 apr vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: APR could be made to expose sensitive information if it received a specially crafted input. Software Description: - apr: Apache Portable Runtime Library Details: It was discovered that APR incorrectly handled certain inputs. An attacker could possibly use this issue to expose sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: libapr1 1.7.0-6ubuntu0.1 Ubuntu 16.04 ESM: libapr1 1.5.2-3ubuntu0.1~esm1 Ubuntu 14.04 ESM: libapr1 1.5.0-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5056-1 CVE-2021-35940 Package Information: https://launchpad.net/ubuntu/+source/apr/1.7.0-6ubuntu0.1 . Security alert USN-5057-1 outlines a critical flaw in the APR library that might lead to unauthorized access to sensitive data on Ubuntu platforms.. Ubuntu Security Advisory, APR Vulnerability, Information Exposure. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.