Skip to content

[3.18] main/apr: security upgrade to 1.7.5

Daniel Néri requested to merge dne/aports:3.18-apr-1.7.5 into 3.18-stable

Fix CVE-2023-49582: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h)

Merge request reports

Loading