Subject: Bug#655435: libapr1: apr_hash vulnerable to oCert-2011-003 style DOS attacks
Fixed in 1.4.6

If we need to backport in the future, the changes are located in only two files:
tables/apr_hash.c
test/testhash.c

Attached patch was taken from upstream trunk, it can also apply to previous
versions, including 1.4.2-6+squeeze3
(C)2011 mailinglist-archive.com