The vendor explicitly identifies these products as affected by this CVE.
- apr-util-devel as a component of Red Hat Enterprise Linux 10
- apr-util-ldap as a component of Red Hat Enterprise Linux 10
- apr-util-lmdb as a component of Red Hat Enterprise Linux 10
- apr-util-mysql as a component of Red Hat Enterprise Linux 10
- apr-util-odbc as a component of Red Hat Enterprise Linux 10
- apr-util-openssl as a component of Red Hat Enterprise Linux 10
- apr-util-pgsql as a component of Red Hat Enterprise Linux 10
- apr-util-sqlite as a component of Red Hat Enterprise Linux 10
- apr-util.src as a component of Red Hat Enterprise Linux 10
- apr-util as a component of Red Hat Enterprise Linux 6
- apr-util-devel as a component of Red Hat Enterprise Linux 6
- apr-util-ldap as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in the Redis client in the Apache Portable Runtime Utility (apr-util). A heap buffer overflow can be triggered when the application processes a specially crafted response from a Redis server, resulting in a crash and denial of service.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
