GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sun May 18, 2014 10:26 pm Post subject: [ GLSA 201405-24 ] Apache Portable Runtime, APR Utility Libr |
|
|
Gentoo Linux Security Advisory
Title: Apache Portable Runtime, APR Utility Library: Denial of Service (GLSA 201405-24)
Severity: low
Exploitable: remote
Date: May 18, 2014
Bug(s): #339527, #366903, #368651, #399089
ID: 201405-24
Synopsis
Memory consumption errors in Apache Portable Runtime and APR
Utility Library could result in Denial of Service.
Background
The Apache Portable Runtime (aka APR) provides a set of APIs for
creating platform-independent applications. The Apache Portable Runtime
Utility Library (aka APR-Util) provides an interface to functionality
such as XML parsing, string matching and database connections.
Affected Packages
Package: dev-libs/apr
Vulnerable: < 1.4.8-r1
Unaffected: >= 1.4.8-r1
Architectures: All supported architectures
Package: dev-libs/apr-util
Vulnerable: < 1.3.10
Unaffected: >= 1.3.10
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Apache Portable Runtime
and APR Utility Library. Please review the CVE identifiers referenced
below for details.
Impact
A remote attacker could cause a Denial of Service condition.
Workaround
There is no known workaround at this time.
Resolution
All Apache Portable Runtime users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/apr-1.4.8-r1"
| All users of the APR Utility Library should upgrade to the latest
version:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/apr-util-1.3.10"
| Packages which depend on these libraries may need to be recompiled.
Tools such as revdep-rebuild may assist in identifying some of these
packages.
References
CVE-2010-1623
CVE-2011-0419
CVE-2011-1928
CVE-2012-0840 |
|