USN-5885-1: APR vulnerability
27 February 2023
APR could possibly be made to crash or run programs if it received specially crafted network traffic.
Releases
Packages
- apr - Apache Portable Runtime Library
Details
Ronald Crane discovered integer overflow vulnerabilities in the Apache
Portable Runtime (APR) that could potentially result in memory corruption.
A remote attacker could possibly use these issues to cause a denial of
service or execute arbitary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
Ubuntu 22.04
In general, a standard system update will make all the necessary changes.