An apr-util security update has been released for Debian GNU/Linux 8 and 9 Extended LTS to address multiple vulnerabilities.

ELA-813-1 apr-util security update

Package : apr-util
Version : 1.5.4-1+deb8u1 (jessie), 1.5.4-3+deb9u1 (stretch)

Related CVEs :

apr-util, Apache Portable Runtime Utility Library, had multiple

apr-util fails to validate the integrity of SDBM database files
used by apr_sdbm*() functions, resulting in a possible out of
bound read access. A local user with write access to the database
can make a program or process using these functions crash, and
cause a denial of service.

Integer Overflow or Wraparound vulnerability in apr_base64
functions of apr-util allows an attacker to write beyond bounds
of a buffer.

