| Release | Version |
|---|---|
| bullseye | 1.6.1-5+deb11u1 |
| bookworm | 1.6.3-1 |
| trixie | 1.6.3-3 |
| trixie (security) | 1.6.3-3+deb13u1 |
| forky | 1.6.4-2 |
| sid | 1.6.4-2 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-34502 | vulnerable | vulnerable | fixed | fixed | fixed | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ... |
| CVE-2026-34501 | vulnerable | vulnerable | fixed | fixed | fixed | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ... |
| CVE-2026-32327 | vulnerable | vulnerable | fixed | fixed | fixed | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ... |
| CVE-2025-49506 | vulnerable | vulnerable | fixed | fixed | fixed | APR-util versions 1.6.3 (and earlier) function apr_password_validate() ... |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-34191 | vulnerable | vulnerable | fixed | fixed | fixed | Improper Neutralization of Special Elements used in an SQL Command ('S ... |
| Bug | Description |
|---|---|
| CVE-2022-25147 | Integer Overflow or Wraparound vulnerability in apr_base64 functions o ... |
| CVE-2017-12618 | Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to val ... |
| CVE-2016-6312 | The mod_dontdothat component of the mod_dav_svn Apache module in Subve ... |
| CVE-2010-1623 | Memory leak in the apr_brigade_split_line function in buckets/apr_brig ... |
| CVE-2009-2412 | Multiple integer overflows in the Apache Portable Runtime (APR) librar ... |
| CVE-2009-1956 | Off-by-one error in the apr_brigade_vprintf function in Apache APR-uti ... |
| CVE-2009-1955 | The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Ap ... |
| CVE-2009-0023 | The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apa ... |
| DSA / DLA | Description |
|---|---|
| DSA-6437-1 | apr-util - security update |
| DSA-5364-1 | apr-util - security update |
| DLA-3332-1 | apr-util - security update |
| DLA-1163-1 | apr-util - security update |
| DSA-2117-1 | apr-util - denial of service |
| DSA-1854-1 | apr apr-util - arbitrary code execution |
| DSA-1812-1 | apr-util - several vulnerabilities |