aboutsummaryrefslogtreecommitdiffstats
path: root/english/lts/security/2017/dla-1162.wml
blob: 262777a62ebf6b6c34a776954caf130d884d798d (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
<define-tag description>LTS security update</define-tag>
<define-tag moreinfo>
<p>It was discovered that there was an out-of-bounds memory vulnerability
in apr, a support/portability library for various applications.</p>

<p>When the apr_exp_time*() or apr_os_exp_time*() functions were invoked
with an invalid month field value, out of bounds memory may have been be
accessed when converting this value to an apr_time_exp_t value. This
could have potentially revealed the contents of a different static heap
value or resulted in program termination.</p>

<p>For Debian 7 <q>Wheezy</q>, this issue has been fixed in apr version
1.4.6-3+deb7u2.</p>

<p>We recommend that you upgrade your apr packages.</p>
</define-tag>

# do not modify the following line
#include "$(ENGLISHDIR)/lts/security/2017/dla-1162.data"
# $Id: $

© 2014-2024 Faster IT GmbH | imprint | privacy policy