[<prev] [next>] [day] [month] [year] [list]
Message-Id: <E1RxIer-0003xV-FW@titan.mandriva.com>
Date: Tue, 14 Feb 2012 14:43:01 +0100
From: security@...driva.com
To: full-disclosure@...ts.grok.org.uk
Subject: [ MDVSA-2012:019 ] apr
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDVSA-2012:019
http://www.mandriva.com/security/
_______________________________________________________________________
Package : apr
Date : February 14, 2012
Affected: 2010.1, 2011., Enterprise Server 5.0
_______________________________________________________________________
Problem Description:
A vulnerability has been found and corrected in ASF APR:
tables/apr_hash.c in the Apache Portable Runtime (APR) library through
1.4.5 computes hash values without restricting the ability to trigger
hash collisions predictably, which allows context-dependent attackers
to cause a denial of service (CPU consumption) via crafted input to
an application that maintains a hash table (CVE-2012-0840).
APR has been upgraded to the latest version (1.4.6) which holds
many improvments over the previous versions and is not vulnerable to
this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0840
http://www.apache.org/dist/apr/CHANGES-APR-1.4
_______________________________________________________________________
Updated Packages:
Mandriva Linux 2010.1:
1de7664f663207ff2e2b66ed38059f04 2010.1/i586/libapr1-1.4.6-0.1mdv2010.2.i586.rpm
f371aea1ad44fcdbc45d63c759ef7fb0 2010.1/i586/libapr-devel-1.4.6-0.1mdv2010.2.i586.rpm
698b79ec7009e77ba8d7d53b71434950 2010.1/SRPMS/apr-1.4.6-0.1mdv2010.2.src.rpm
Mandriva Linux 2010.1/X86_64:
d3f53d0a19a448ffc48bb000278e0284 2010.1/x86_64/lib64apr1-1.4.6-0.1mdv2010.2.x86_64.rpm
04118f9682910695ba84d82a32c98c32 2010.1/x86_64/lib64apr-devel-1.4.6-0.1mdv2010.2.x86_64.rpm
698b79ec7009e77ba8d7d53b71434950 2010.1/SRPMS/apr-1.4.6-0.1mdv2010.2.src.rpm
Mandriva Linux 2011:
1a06fc6721c20f950a04dc067344bbe4 2011/i586/libapr1-1.4.6-0.1-mdv2011.0.i586.rpm
ba7aaaaadf1e8336afb4c43b03cb9054 2011/i586/libapr-devel-1.4.6-0.1-mdv2011.0.i586.rpm
408e2ed975392cc47e9c0e6dce697d12 2011/SRPMS/apr-1.4.6-0.1.src.rpm
Mandriva Linux 2011/X86_64:
9d4e2c286abf5a227512c75b3f0ccb18 2011/x86_64/lib64apr1-1.4.6-0.1-mdv2011.0.x86_64.rpm
05a9e3242ea9058d591849c035960c55 2011/x86_64/lib64apr-devel-1.4.6-0.1-mdv2011.0.x86_64.rpm
408e2ed975392cc47e9c0e6dce697d12 2011/SRPMS/apr-1.4.6-0.1.src.rpm
Mandriva Enterprise Server 5:
173d17df305532e677eacb61427fc290 mes5/i586/libapr1-1.4.6-0.1mdvmes5.2.i586.rpm
cd21d21a2fef2b9cc5b5f13c3bb78e74 mes5/i586/libapr-devel-1.4.6-0.1mdvmes5.2.i586.rpm
9eb866bcc8c407845edf67c6be078bcc mes5/SRPMS/apr-1.4.6-0.1mdvmes5.2.src.rpm
Mandriva Enterprise Server 5/X86_64:
029327d54965590a23af96af702af87a mes5/x86_64/lib64apr1-1.4.6-0.1mdvmes5.2.x86_64.rpm
c8f4a0942de90fef566282be2272b0e3 mes5/x86_64/lib64apr-devel-1.4.6-0.1mdvmes5.2.x86_64.rpm
9eb866bcc8c407845edf67c6be078bcc mes5/SRPMS/apr-1.4.6-0.1mdvmes5.2.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iD8DBQFPOja+mqjQ0CJFipgRAp9EAJ4qEv7J7UE2wjx5qker0jmSjb1w0QCfd5ww
8aKnTFrwxpgClJVD3/1GqCI=
=EGzk
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists