Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 201405-24 ] Apache Portable Runtime, APR Utility Library: Denial of Service
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Veteran
Veteran


Joined: 12 May 2004
Posts: 1567

PostPosted: Sun May 18, 2014 10:26 pm    Post subject: [ GLSA 201405-24 ] Apache Portable Runtime, APR Utility Libr Reply with quote

Gentoo Linux Security Advisory

Title: Apache Portable Runtime, APR Utility Library: Denial of Service (GLSA 201405-24)
Severity: low
Exploitable: remote
Date: May 18, 2014
Bug(s): #339527, #366903, #368651, #399089
ID: 201405-24

Synopsis

Memory consumption errors in Apache Portable Runtime and APR
Utility Library could result in Denial of Service.


Background

The Apache Portable Runtime (aka APR) provides a set of APIs for
creating platform-independent applications. The Apache Portable Runtime
Utility Library (aka APR-Util) provides an interface to functionality
such as XML parsing, string matching and database connections.


Affected Packages

Package: dev-libs/apr
Vulnerable: < 1.4.8-r1
Unaffected: >= 1.4.8-r1
Architectures: All supported architectures

Package: dev-libs/apr-util
Vulnerable: < 1.3.10
Unaffected: >= 1.3.10
Architectures: All supported architectures


Description

Multiple vulnerabilities have been discovered in Apache Portable Runtime
and APR Utility Library. Please review the CVE identifiers referenced
below for details.


Impact

A remote attacker could cause a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All Apache Portable Runtime users should upgrade to the latest version:
Code:
# emerge --sync
      # emerge --ask --oneshot --verbose ">=dev-libs/apr-1.4.8-r1"
   
All users of the APR Utility Library should upgrade to the latest
version:
Code:
# emerge --sync
      # emerge --ask --oneshot --verbose ">=dev-libs/apr-util-1.3.10"
   
Packages which depend on these libraries may need to be recompiled.
Tools such as revdep-rebuild may assist in identifying some of these
packages.


References

CVE-2010-1623
CVE-2011-0419
CVE-2011-1928
CVE-2012-0840
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum