[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2010-0950 -- Oracle apr-util

ID: oval:org.secpod.oval:def:1503294Date: (C)2021-01-08   (M)2023-11-09
Class: PATCHFamily: unix




Updated apr-util packages that fix one security issue are now available for Red Hat Enterprise Linux 4, 5, and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System base score, which gives a detailed severity rating, is available from the CVE link in the References section. Description The Apache Portable Runtime is a portability library used by the Apache HTTP Server and other projects. apr-util is a library which provides additional utility interfaces for APR; including support for XML parsing, LDAP, database interfaces, URI parsing, and more. It was found that certain input could cause the apr-util library to allocate more memory than intended in the apr_brigade_split_line function. An attacker able to provide input in small chunks to an application using the apr-util library could possibly use this flaw to trigger high memory consumption. All apr-util users should upgrade to these updated packages, which contain a backported patch to correct this issue. Applications using the apr-util library, such as httpd, must be restarted for this update to take effect.

Platform:
Oracle Linux 6
Product:
apr-util
Reference:
ELSA-2010-0950
CVE-2010-1623
CVE    1
CVE-2010-1623
CPE    2
cpe:/a:apache:apr-util
cpe:/o:oracle:linux:6

© SecPod Technologies