Chapter 1. Package Updates
1.8. apr
1.8.1. RHSA-2009:1204: Moderate and apr-util security update
Important
This update has already been released (prior to the GA of this release) as the security
RHSA-2009:1204
errata
Updated apr and apr-util packages that fix multiple security issues are now available for Red Hat
Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and
other projects. It aims to provide a free library of C data structures and routines. apr-util is a utility
library used with APR. This library provides additional utility interfaces for APR; including support for
XML parsing, LDAP, database interfaces, URI parsing, and more.
Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in the way the
Apache Portable Runtime (APR) manages memory pool and relocatable memory allocations. An
attacker could use these flaws to issue a specially-crafted request for memory allocation, which would
lead to a denial of service (application crash) or, potentially, execute arbitrary code with the privileges
of an application using the APR libraries.
All apr and apr-util users should upgrade to these updated packages, which contain backported
patches to correct these issues. Applications using the APR libraries, such as httpd, must be restarted
for this update to take effect.
1.9. apr-util
1.9.1. RHSA-2009:1107: Moderate security update
Important
This update has already been released (prior to the GA of this release) as the security
RHSA-2009:1107
errata
Updated apr-util packages that fix multiple security issues are now available for Red Hat Enterprise
Linux 4 and 5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
apr-util is a utility library used with the Apache Portable Runtime (APR). It aims to provide a free library
of C data structures and routines. This library contains additional utility interfaces for APR; including
support for XML, LDAP, database interfaces, URI parsing, and more.
92
https://www.redhat.com/security/data/cve/CVE-2009-2412.html
10
91
92
(CVE-2009-2412
)
93
Need help?
Do you have a question about the ENTERPRISE LINUX 5.4 - TECHNICAL NOTES and is the answer not in the manual?
Questions and answers