Описание
Security update for apache2-mod_auth_openidc
This update for apache2-mod_auth_openidc fixes the following issues:
- CVE-2025-3891: denial of service via POST requests with an empty Content-Type header and with OIDCPreservePost On (bsc#1242015).
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
apache2-mod_auth_openidc-2.4.0-7.22.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
apache2-mod_auth_openidc-2.4.0-7.22.1
Ссылки
- Link for SUSE-SU-2025:01585-1
- E-Mail link for SUSE-SU-2025:01585-1
- SUSE Security Ratings
- SUSE Bug 1242015
- SUSE CVE CVE-2025-3891 page
Описание
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:apache2-mod_auth_openidc-2.4.0-7.22.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:apache2-mod_auth_openidc-2.4.0-7.22.1
Ссылки
- CVE-2025-3891
- SUSE Bug 1242015