Oval Definition:oval:com.redhat.rhsa:def:20100950
Revision Date:2010-12-08Version:638
Title:RHSA-2010:0950: apr-util security update (Moderate)
Description:The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and other projects. apr-util is a library which provides additional utility interfaces for APR; including support for XML parsing, LDAP, database interfaces, URI parsing, and more.

  • It was found that certain input could cause the apr-util library to allocate more memory than intended in the apr_brigade_split_line() function. An attacker able to provide input in small chunks to an application using the apr-util library (such as httpd) could possibly use this flaw to trigger high memory consumption. (CVE-2010-1623)

    All apr-util users should upgrade to these updated packages, which contain a backported patch to correct this issue. Applications using the apr-util library, such as httpd, must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-1623
    CVE-2010-1623
    RHSA-2010:0950
    RHSA-2010:0950-01
    RHSA-2010:0950-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • apr-util is earlier than 0:0.9.4-22.el4_8.3
  • AND apr-util is signed with Red Hat redhatrelease2 key
  • apr-util-devel is earlier than 0:0.9.4-22.el4_8.3
  • AND apr-util-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • apr-util is earlier than 0:1.2.7-11.el5_5.2
  • AND apr-util is signed with Red Hat redhatrelease2 key
  • apr-util-devel is earlier than 0:1.2.7-11.el5_5.2
  • AND apr-util-devel is signed with Red Hat redhatrelease2 key
  • apr-util-docs is earlier than 0:1.2.7-11.el5_5.2
  • AND apr-util-docs is signed with Red Hat redhatrelease2 key
  • apr-util-mysql is earlier than 0:1.2.7-11.el5_5.2
  • AND apr-util-mysql is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • apr-util is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util is signed with Red Hat redhatrelease2 key
  • apr-util-devel is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-devel is signed with Red Hat redhatrelease2 key
  • apr-util-ldap is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-ldap is signed with Red Hat redhatrelease2 key
  • apr-util-mysql is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-mysql is signed with Red Hat redhatrelease2 key
  • apr-util-odbc is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-odbc is signed with Red Hat redhatrelease2 key
  • apr-util-pgsql is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-pgsql is signed with Red Hat redhatrelease2 key
  • apr-util-sqlite is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-sqlite is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • apr-util-mysql is earlier than 0:1.2.7-11.el5_5.2
  • AND apr-util-mysql is signed with Red Hat redhatrelease key
  • apr-util-devel is earlier than 0:1.2.7-11.el5_5.2
  • AND apr-util-devel is signed with Red Hat redhatrelease key
  • apr-util-docs is earlier than 0:1.2.7-11.el5_5.2
  • AND apr-util-docs is signed with Red Hat redhatrelease key
  • apr-util is earlier than 0:1.2.7-11.el5_5.2
  • AND apr-util is signed with Red Hat redhatrelease key
  • OR Package Information
  • Red Hat Enterprise Linux 6 Client is installed
  • OR Red Hat Enterprise Linux 6 Server is installed
  • OR Red Hat Enterprise Linux 6 Workstation is installed
  • OR Red Hat Enterprise Linux 6 ComputeNode is installed
  • AND
  • apr-util-mysql is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-mysql is signed with Red Hat redhatrelease2 key
  • apr-util-odbc is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-odbc is signed with Red Hat redhatrelease2 key
  • apr-util-devel is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-devel is signed with Red Hat redhatrelease2 key
  • apr-util-ldap is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-ldap is signed with Red Hat redhatrelease2 key
  • apr-util is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util is signed with Red Hat redhatrelease2 key
  • apr-util-pgsql is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-pgsql is signed with Red Hat redhatrelease2 key
  • apr-util-sqlite is earlier than 0:1.3.9-3.el6_0.1
  • AND apr-util-sqlite is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • apr-util-devel is earlier than 0:0.9.4-22.el4_8.3
  • AND apr-util-devel is signed with Red Hat master key
  • apr-util is earlier than 0:0.9.4-22.el4_8.3
  • AND apr-util is signed with Red Hat master key
  • BACK