Information on source package apr

Available versions

ReleaseVersion
jessie1.5.1-3+deb8u1
stretch1.5.2-5+deb9u1
buster1.6.5-1
bullseye1.7.0-6+deb11u2
bookworm1.7.2-3+deb12u1
trixie1.7.5-1
sid1.7.5-1

Open issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2023-49582vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)fixedfixedfixedLax permissions set by the Apache Portable Runtime library on Unix pla ...

Resolved issues

BugDescription
CVE-2022-28331On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond ...
CVE-2022-24963Integer Overflow or Wraparound vulnerability in apr_encode functions o ...
CVE-2021-35940An out-of-bounds array read in the apr_time_exp*() functions was fixed ...
CVE-2017-12613When apr_time_exp*() or apr_os_exp_time*() functions are invoked with ...
CVE-2012-0840tables/apr_hash.c in the Apache Portable Runtime (APR) library through ...
CVE-2011-1928The fnmatch implementation in apr_fnmatch.c in the Apache Portable Run ...
CVE-2011-0419Stack consumption vulnerability in the fnmatch implementation in apr_f ...
CVE-2009-2699The Solaris pollset feature in the Event Port backend in poll/unix/por ...
CVE-2009-2412Multiple integer overflows in the Apache Portable Runtime (APR) librar ...

Security announcements

DSA / DLADescription
DSA-5370-1apr - security update
DLA-2897-1apr - security update
ELA-549-1apr - security update
DLA-1162-1apr - security update
DSA-2237-2apr - denial of service
DSA-1854-1apr apr-util - arbitrary code execution

Search for package or bug name: Reporting problems