Fedora 40: apr 2024-b40491b84b Security Advisory Updates
Summary
The mission of the Apache Portable Runtime (APR) is to provide a
free library of C data structures and routines, forming a system
portability layer to as many operating systems as possible,
including Unices, MS Win32, BeOS and OS/2.
Update Information:
This update to the apr package fixes a security issue in the handling of shared memory permissions. SECURITY: CVE-2023-49582: Apache Portable Runtime (APR): Unexpected lax shared memory permissions (cve.mitre.org) Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data.
Change Log
* Wed Aug 28 2024 Joe Orton
References
[ 1 ] Bug #2308487 - CVE-2023-49582 apr: Lax permissions in Apache Portable Runtime shared memory [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2308487
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b40491b84b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label