RHSA-2023:3178: Important: apr-util security update
The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and other projects. apr-util is a library which provides additional utility interfaces for APR; including support for XML parsing, LDAP, database interfaces, URI parsing, and more.Security Fix(es): apr-util: out-of-bounds writes in the aprbase64 (CVE-2022-25147) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/apr-utilto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-bdbto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-bdb-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-develto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-ldapto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-mysqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-mysql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-odbcto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-opensslto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-openssl-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-pgsqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-sqliteto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-util-sqlite-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1 - Upgrade
Upgrade
redhat/apr-utilto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-bdbto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-bdb-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-develto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-ldapto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-mysqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-mysql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-odbcto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-opensslto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-openssl-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-pgsqlto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-sqliteto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
redhat/apr-util-sqlite-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1.aa - Upgrade
Upgrade
apr-utilto a version that resolves this vulnerability.Fixed in 1.6.1-6.el8_6.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3178?
The RHSA-2023:3178 vulnerability has been classified as important.
How do I fix RHSA-2023:3178?
To fix RHSA-2023:3178, upgrade the affected packages to version 1.6.1-6.el8_6.1 or later.
Which packages are affected by RHSA-2023:3178?
Affected packages include apr-util, apr-util-bdb, apr-util-devel, apr-util-ldap, and several others as listed in the advisory.
Are there any known exploits for RHSA-2023:3178?
As of now, there are no widely reported exploits specifically targeting RHSA-2023:3178.
What software uses the Apache Portable Runtime affected in RHSA-2023:3178?
Software using the Apache Portable Runtime includes the Apache HTTP Server and various other projects reliant on APR libraries.