DSA-1854-1

NameDSA-1854-1
SourceDebian
Descriptionapr apr-util - arbitrary code execution
ReferencesCVE-2009-2412
Debian/oldstablepackages apr, apr-util are fixed in oldstable-security.
Debian/stablenot vulnerable
Debian/testingnot known to be vulnerable
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apr (PTS)etch1.2.7-8.2vulnerable
etch (security)1.2.7-9fixed
lenny, lenny (security)1.2.12-5+lenny1fixed
apr-util (PTS)etch1.2.7+dfsg-2vulnerable
etch (security)1.2.7+dfsg-2+etch3fixed
lenny, lenny (security)1.2.12+dfsg-8+lenny4fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
libapr1, libapr1-dbg, libapr1-devetch1.2.7-8.2vulnerablealpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
etch (security)1.2.7-9fixedalpha, amd64, arm, i386, ia64, mips, mipsel, powerpc, s390, sparc
lenny, lenny (security)1.2.12-5+lenny1fixedalpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
libaprutil1, libaprutil1-dbg, libaprutil1-devetch1.2.7+dfsg-2vulnerablealpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
etch (security)1.2.7+dfsg-2+etch3fixedalpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
lenny, lenny (security)1.2.12+dfsg-8+lenny4fixedalpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aprsourceetch1.2.7-9unknown
aprsourcelenny1.2.12-5+lenny1unknown
apr-utilsourceetch1.2.7+dfsg-2+etch3unknown
apr-utilsourcelenny1.2.12+dfsg-8+lenny4unknown

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint