Debian Linux Security Advisory 5364-1 - Ronald Crane discovered that missing input saniting in the apr_base64 functions of apr-util, the Apache Portable Runtime utility library, may result in denial of service or potentially the execution of arbitrary code.
0fd080fc2d20d8613ace2e272ac779ee75f49f96590d76bbadc9811f312aedf2
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5364-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
February 26, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : apr-util
CVE ID : CVE-2022-25147
Ronald Crane discovered that missing input saniting in the apr_base64
functions of apr-util, the Apache Portable Runtime utility library, may
result in denial of service or potentially the execution of arbitrary
code.
For the stable distribution (bullseye), this problem has been fixed in
version 1.6.1-5+deb11u1.
We recommend that you upgrade your apr-util packages.
For the detailed security status of apr-util please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/apr-util
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmP7XXNfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QB3Q/9HyXeMjxWnq4JsTDF+LZvv13WdUVhuaKmhoe7LAg7HLUYy1F49LNQGfBN
y2bmg/Ggp/ga+Vb+7F+A2/OpF38AaLaMyREbnaqU2XHM25Zp2LlITjZsf3lI42Tw
iyiiWjhBFd2cGnLrnGkghz4wBTEdU5OUTvKg5987y0FwuapCs4FoW7xCEzsLNkun
pcbwyhh7mljVnXKl2gJ73q81cseGOB0BOyfxK3KMV+9pOhJ12OJsY61BpOspFuzV
0yZHyNTQduqy6wWUecRyl7tiOed4CcS5zCLQNBlqoXyvyhg6+rzyQWPWAwyDwP+v
R2hDEPt7hH8ejbeloY+Gqp6Fi1gxdOtKphFyGKRe6BuLGyFHK4M1eJUCqHOqQTuF
tgTNNRCz8Km5bJGIPo9lkwHfGySSUJ9KEECEoMj6eTvpJUlyt0hPLQsM6vzcu6eT
WiJAOQauoprhOK5V4Hh2pF7G0zqPqkKK13962EsbODdkOTHzDA99ocqgYjOzTp9x
ZM7ivuXTnMexMJJu7eew8VYSKChNZB3BeTKoAkXoRev0kSROr2VznnPjqyIuocEv
cypG9k5/6Fpb6VwFtxQuqZRLri0xqqWr2ZTczDTeCC7X/jDdt53zKCEVv7exx/h6
LBDOilmr/BZwyciX5y+e6wVEx5PK67LkwGlx+4ZaSqAKDUYdm50=Twof
-----END PGP SIGNATURE-----