Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5364-1] apr-util security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5364-1] apr-util security update


Chronologisch Thread  
  • From: Salvatore Bonaccorso <carnil AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5364-1] apr-util security update
  • Date: Sun, 26 Feb 2023 13:27:25 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
  • List-archive: https://lists.debian.org/msgid-search/E1pWH3l-00DdSN-FX AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=LUaa2wXvcr9au1L0Gy3nG7AvJfLc//SwjvRXS7sqbNQ=; b=JC 266Xc9U5aRShqWmvPe6hmRnMqddEEqu4jUFZyyLEbdLBZGHo1qj9IgRD9sLJPypkQPOcCZvHbqUhW IG8kRwHdG5Axi64onyunzRNfeN0aqX6Tg9ghpo4U3ybZbgRIHTrtZ03+RXOdPWrfQ/4G+VB+dE0Y3 JXW++gei0oE3yYmFx3uLHVu4YURGSRpQtaeLJ2p3EvJl1xFOm2CYktlAoHl/VqyAFAFyVpfqudEBs UbukZu9D12/6mNxfRnjSpzCwEdK1ENxmAH3ApQ/k1sK9g0CXnrNTs6Krfrlt3KGQJfSHDvjLsM8r9 bnXh4T+a/K0wnwOpdyg/8S38H3t38wYQ==;
  • Old-return-path: <carnil AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Sun, 26 Feb 2023 13:27:49 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <MX-8c5olTHN.A.OwE.U51-jB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5364-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
February 26, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : apr-util
CVE ID : CVE-2022-25147

Ronald Crane discovered that missing input saniting in the apr_base64
functions of apr-util, the Apache Portable Runtime utility library, may
result in denial of service or potentially the execution of arbitrary
code.

For the stable distribution (bullseye), this problem has been fixed in
version 1.6.1-5+deb11u1.

We recommend that you upgrade your apr-util packages.

For the detailed security status of apr-util please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/apr-util

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmP7XXNfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QB3Q/9HyXeMjxWnq4JsTDF+LZvv13WdUVhuaKmhoe7LAg7HLUYy1F49LNQGfBN
y2bmg/Ggp/ga+Vb+7F+A2/OpF38AaLaMyREbnaqU2XHM25Zp2LlITjZsf3lI42Tw
iyiiWjhBFd2cGnLrnGkghz4wBTEdU5OUTvKg5987y0FwuapCs4FoW7xCEzsLNkun
pcbwyhh7mljVnXKl2gJ73q81cseGOB0BOyfxK3KMV+9pOhJ12OJsY61BpOspFuzV
0yZHyNTQduqy6wWUecRyl7tiOed4CcS5zCLQNBlqoXyvyhg6+rzyQWPWAwyDwP+v
R2hDEPt7hH8ejbeloY+Gqp6Fi1gxdOtKphFyGKRe6BuLGyFHK4M1eJUCqHOqQTuF
tgTNNRCz8Km5bJGIPo9lkwHfGySSUJ9KEECEoMj6eTvpJUlyt0hPLQsM6vzcu6eT
WiJAOQauoprhOK5V4Hh2pF7G0zqPqkKK13962EsbODdkOTHzDA99ocqgYjOzTp9x
ZM7ivuXTnMexMJJu7eew8VYSKChNZB3BeTKoAkXoRev0kSROr2VznnPjqyIuocEv
cypG9k5/6Fpb6VwFtxQuqZRLri0xqqWr2ZTczDTeCC7X/jDdt53zKCEVv7exx/h6
LBDOilmr/BZwyciX5y+e6wVEx5PK67LkwGlx+4ZaSqAKDUYdm50=
=Twof
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5364-1] apr-util security update, Salvatore Bonaccorso, 26.02.2023

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang