-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5364-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso February 26, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : apr-util CVE ID : CVE-2022-25147 Ronald Crane discovered that missing input saniting in the apr_base64 functions of apr-util, the Apache Portable Runtime utility library, may result in denial of service or potentially the execution of arbitrary code. For the stable distribution (bullseye), this problem has been fixed in version 1.6.1-5+deb11u1. We recommend that you upgrade your apr-util packages. For the detailed security status of apr-util please refer to its security tracker page at: https://security-tracker.debian.org/tracker/apr-util Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmP7XXNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0QB3Q/9HyXeMjxWnq4JsTDF+LZvv13WdUVhuaKmhoe7LAg7HLUYy1F49LNQGfBN y2bmg/Ggp/ga+Vb+7F+A2/OpF38AaLaMyREbnaqU2XHM25Zp2LlITjZsf3lI42Tw iyiiWjhBFd2cGnLrnGkghz4wBTEdU5OUTvKg5987y0FwuapCs4FoW7xCEzsLNkun pcbwyhh7mljVnXKl2gJ73q81cseGOB0BOyfxK3KMV+9pOhJ12OJsY61BpOspFuzV 0yZHyNTQduqy6wWUecRyl7tiOed4CcS5zCLQNBlqoXyvyhg6+rzyQWPWAwyDwP+v R2hDEPt7hH8ejbeloY+Gqp6Fi1gxdOtKphFyGKRe6BuLGyFHK4M1eJUCqHOqQTuF tgTNNRCz8Km5bJGIPo9lkwHfGySSUJ9KEECEoMj6eTvpJUlyt0hPLQsM6vzcu6eT WiJAOQauoprhOK5V4Hh2pF7G0zqPqkKK13962EsbODdkOTHzDA99ocqgYjOzTp9x ZM7ivuXTnMexMJJu7eew8VYSKChNZB3BeTKoAkXoRev0kSROr2VznnPjqyIuocEv cypG9k5/6Fpb6VwFtxQuqZRLri0xqqWr2ZTczDTeCC7X/jDdt53zKCEVv7exx/h6 LBDOilmr/BZwyciX5y+e6wVEx5PK67LkwGlx+4ZaSqAKDUYdm50=Twof -----END PGP SIGNATURE-----