RHSA-2023:3109: Important: apr-util security update
The Apache Portable Runtime (APR) is a portability library used by theApache HTTP Server and other projects. apr-util is a library which providesadditional utility interfaces for APR; including support for XML parsing,LDAP, database interfaces, URI parsing, and more.Security Fix(es): apr-util: out-of-bounds writes in the aprbase64 (CVE-2022-25147) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/apr-utilto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-bdbto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-bdb-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-develto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-ldapto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-mysqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-mysql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-odbcto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-opensslto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-openssl-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-pgsqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-sqliteto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-util-sqlite-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
redhat/apr-utilto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-bdbto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-bdb-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-develto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-ldapto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-mysqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-mysql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-odbcto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-opensslto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-openssl-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-pgsqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-sqliteto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
redhat/apr-util-sqlite-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1.aa - Upgrade
Upgrade
apr-utilto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
apr-util-bdbto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
apr-util-ldapto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
apr-util-mysqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
apr-util-odbcto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
apr-util-opensslto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
apr-util-pgsqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1 - Upgrade
Upgrade
apr-util-sqliteto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_8.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3109?
The severity of RHSA-2023:3109 is classified as important.
How do I fix RHSA-2023:3109?
To fix RHSA-2023:3109, you should update the affected packages to version 1.6.1-6.el8_8.1 or higher.
What packages are affected by RHSA-2023:3109?
The affected packages for RHSA-2023:3109 include apr-util, apr-util-bdb, apr-util-devel, and others.
When was RHSA-2023:3109 issued?
RHSA-2023:3109 was issued on October 5, 2023.
Is there a workaround for RHSA-2023:3109 until it is fixed?
There are no documented workarounds for RHSA-2023:3109; updating is recommended.