Описание
Recommended update for apache2
This update for the Apache Web Server introduces directives to control two protocol options:
MODULE_MAGIC_NUMBER_MINOR has been increased to 24, as this change is not forward-compatible. Modules built against this release might not work correctly with older releases of the Apache Web Server.
Список пакетов
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP3
SUSE Linux Enterprise Software Development Kit 11 SP3
Ссылки
- Link for SUSE-SU-2015:0689-1
- E-Mail link for SUSE-SU-2015:0689-1
- SUSE Security Ratings
- SUSE Bug 713970
- SUSE Bug 791794
- SUSE Bug 815621
- SUSE Bug 829056
- SUSE Bug 829057
- SUSE Bug 844212
- SUSE Bug 852401
- SUSE Bug 859916
- SUSE Bug 869105
- SUSE Bug 869106
- SUSE Bug 871310
- SUSE Bug 887765
- SUSE Bug 887768
- SUSE Bug 894225
- SUSE Bug 899836
- SUSE Bug 904427
- SUSE Bug 907339
Описание
Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).
Затронутые продукты
Ссылки
- CVE-2003-1418
- SUSE Bug 713970
- SUSE Bug 907477
- SUSE Bug 917402
- SUSE Bug 970126
Описание
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
Затронутые продукты
Ссылки
- CVE-2013-1862
- SUSE Bug 829056
- SUSE Bug 829057
- SUSE Bug 834475
- SUSE Bug 844212
Описание
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
Затронутые продукты
Ссылки
- CVE-2013-1896
- SUSE Bug 829056
- SUSE Bug 829057
Описание
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
Затронутые продукты
Ссылки
- CVE-2013-5704
- SUSE Bug 871310
- SUSE Bug 914535
- SUSE Bug 930944
- SUSE Bug 938728
Описание
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
Затронутые продукты
Ссылки
- CVE-2013-6438
- SUSE Bug 869105
- SUSE Bug 869106
- SUSE Bug 887765
Описание
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
Затронутые продукты
Ссылки
- CVE-2014-0098
- SUSE Bug 869106
- SUSE Bug 887765
Описание
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.
Затронутые продукты
Ссылки
- CVE-2014-0226
- SUSE Bug 887765
Описание
The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
Затронутые продукты
Ссылки
- CVE-2014-0231
- SUSE Bug 887768
Описание
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.
Затронутые продукты
Ссылки
- CVE-2014-3581
- SUSE Bug 899836