RHSA-2023:3360: Moderate: apr-util security update
The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and other projects. "apr-util" is a library which provides additional utility interfaces for APR; including support for XML parsing, LDAP, database interfaces, URI parsing, and moreSecurity Fix(es): apr-util: out-of-bounds writes in the aprbase64 (CVE-2022-25147) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/apr-utilto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-bdbto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-bdb-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-develto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-ldapto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-mysqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-mysql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-odbcto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-opensslto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-openssl-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-pgsqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-sqliteto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-util-sqlite-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1 - Upgrade
Upgrade
redhat/apr-utilto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-bdbto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-bdb-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-develto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-ldapto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-mysqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-mysql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-odbcto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-opensslto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-openssl-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-pgsqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-sqliteto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa - Upgrade
Upgrade
redhat/apr-util-sqlite-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_4.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3360?
The severity of RHSA-2023:3360 is categorized as a high risk affecting the Apache Portable Runtime (APR).
How do I fix RHSA-2023:3360?
To fix RHSA-2023:3360, update the affected package to version 1.6.1-6.el8_4.1 or newer.
Which packages are affected by RHSA-2023:3360?
Affected packages include apr-util, apr-util-bdb, apr-util-devel, apr-util-ldap, and several others listed in the advisory.
Is there a workaround for RHSA-2023:3360?
There is no specific workaround for RHSA-2023:3360; updating to the fixed version is recommended.
When was RHSA-2023:3360 released?
RHSA-2023:3360 was released on October 3, 2023.