CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
APR-util versions 1.6.3 (and earlier) function aprpasswordvalidate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Portable Runtime Utility (APR-util)to a version that resolves this vulnerability.Fixed in 1.6.4