-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
______________________________________________________________________________
SUSE Security Announcement
Package: apache2,libapr1
Announcement ID: SUSE-SA:2009:050
Date: Mon, 26 Oct 2009 12:00:00 +0000
Affected Products: openSUSE 10.3
openSUSE 11.0
openSUSE 11.1
SUSE SLES 9
Novell Linux Desktop 9
Open Enterprise Server
Novell Linux POS 9
SLE SDK 10 SP2
SLE SDK 10 SP3
SUSE Linux Enterprise Desktop 10 SP2
SUSE Linux Enterprise Desktop 10 SP3
SUSE Linux Enterprise 10 SP2 DEBUGINFO
SUSE Linux Enterprise Server 10 SP2
SUSE Linux Enterprise 10 SP3 DEBUGINFO
SUSE Linux Enterprise Server 10 SP3
SLES 11 DEBUGINFO
SLE 11
SLES 11
Vulnerability Type: potential code execution
remote denial of service
Severity (1-10): 8
SUSE Default Package: no
Cross-References: CVE-2009-1195, CVE-2009-1890, CVE-2009-1891
CVE-2009-2412, CVE-2009-3094, CVE-2009-3095
Content of This Advisory:
1) Security Vulnerability Resolved:
Apache and libapr1 security updates
Problem Description
2) Solution or Work-Around
3) Special Instructions and Notes
4) Package Location and Checksums
5) Pending Vulnerabilities, Solutions, and Work-Arounds:
See SUSE Security Summary Report.
6) Authenticity Verification and Additional Information
______________________________________________________________________________
1) Problem Description and Brief Discussion
The Apache web server was updated to fix various security issues:
- the option IncludesNOEXEC could be bypassed via .htaccess (CVE-2009-1195)
- mod_proxy could run into an infinite loop when used as reverse proxy
(CVE-2009-1890)
- mod_deflate continued to compress large files even after a network
connection was closed, causing mod_deflate to consume large amounts
of CPU (CVE-2009-1891)
- The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in
the mod_proxy_ftp module allows remote FTP servers to cause a denial
of service (NULL pointer dereference and child process crash) via a
malformed reply to an EPSV command. (CVE-2009-3094)
- access restriction bypass in mod_proxy_ftp module (CVE-2009-3095)
Also the libapr1 and libapr-util1 Apache helper libraries were updated
to fix multiple integer overflows that could probably be used to
execute arbitrary code remotely. (CVE-2009-2412)
2) Solution or Work-Around
There is no known workaround, please install the update packages.
3) Special Instructions and Notes
Please close and restart all running instances of Apache after the update.
4) Package Location and Checksums
The preferred method for installing security updates is to use the YaST
Online Update (YOU) tool. YOU detects which updates are required and
automatically performs the necessary steps to verify and install them.
Alternatively, download the update packages for your distribution manually
and verify their integrity by the methods listed in Section 6 of this
announcement. Then install the packages using the command
rpm -Fhv
to apply the update, replacing with the filename of the
downloaded RPM package.
x86 Platform:
openSUSE 11.1:
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/i586/apache2-debuginfo-2.2.10-2.8.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/i586/apache2-debugsource-2.2.10-2.8.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/i586/libapr-util1-debuginfo-1.3.4-13.3.2.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/i586/libapr-util1-debugsource-1.3.4-13.3.2.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/i586/libapr1-debuginfo-1.3.3-12.2.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/i586/libapr1-debugsource-1.3.3-12.2.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/apache2-2.2.10-2.8.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/apache2-devel-2.2.10-2.8.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/apache2-doc-2.2.10-2.8.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/apache2-example-pages-2.2.10-2.8.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/apache2-prefork-2.2.10-2.8.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/apache2-utils-2.2.10-2.8.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/apache2-worker-2.2.10-2.8.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/libapr-util1-1.3.4-13.3.2.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/libapr-util1-dbd-mysql-1.3.4-13.3.2.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/libapr-util1-dbd-pgsql-1.3.4-13.3.2.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/libapr-util1-dbd-sqlite3-1.3.4-13.3.2.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/libapr-util1-devel-1.3.4-13.3.2.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/libapr1-1.3.3-12.2.1.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/libapr1-devel-1.3.3-12.2.1.i586.rpm
openSUSE 11.0:
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/apache2-2.2.8-28.8.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/apache2-devel-2.2.8-28.8.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/apache2-doc-2.2.8-28.8.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/apache2-example-pages-2.2.8-28.8.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/apache2-prefork-2.2.8-28.8.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/apache2-utils-2.2.8-28.8.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/apache2-worker-2.2.8-28.8.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/libapr-util1-1.2.12-43.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/libapr-util1-dbd-mysql-1.2.12-43.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/libapr-util1-dbd-pgsql-1.2.12-43.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/libapr-util1-dbd-sqlite3-1.2.12-43.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/libapr-util1-devel-1.2.12-43.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/libapr1-1.2.12-27.2.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/libapr1-devel-1.2.12-27.2.i586.rpm
openSUSE 10.3:
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/apache2-2.2.4-70.11.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/apache2-devel-2.2.4-70.11.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/apache2-doc-2.2.4-70.11.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/apache2-example-pages-2.2.4-70.11.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/apache2-prefork-2.2.4-70.11.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/apache2-utils-2.2.4-70.11.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/apache2-worker-2.2.4-70.11.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/libapr-util1-1.2.8-68.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/libapr-util1-dbd-mysql-1.2.8-68.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/libapr-util1-dbd-pgsql-1.2.8-68.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/libapr-util1-dbd-sqlite3-1.2.8-68.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/libapr-util1-devel-1.2.8-68.4.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/libapr1-1.2.9-9.2.i586.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/libapr1-devel-1.2.9-9.2.i586.rpm
Power PC Platform:
openSUSE 11.1:
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/ppc/apache2-debuginfo-2.2.10-2.8.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/ppc/apache2-debugsource-2.2.10-2.8.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/ppc/libapr-util1-debuginfo-1.3.4-13.3.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/ppc/libapr-util1-debugsource-1.3.4-13.3.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/ppc/libapr1-debuginfo-1.3.3-12.2.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/ppc/libapr1-debugsource-1.3.3-12.2.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/apache2-2.2.10-2.8.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/apache2-devel-2.2.10-2.8.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/apache2-doc-2.2.10-2.8.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/apache2-example-pages-2.2.10-2.8.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/apache2-prefork-2.2.10-2.8.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/apache2-utils-2.2.10-2.8.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/apache2-worker-2.2.10-2.8.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/libapr-util1-1.3.4-13.3.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/libapr-util1-dbd-mysql-1.3.4-13.3.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/libapr-util1-dbd-pgsql-1.3.4-13.3.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/libapr-util1-dbd-sqlite3-1.3.4-13.3.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/libapr-util1-devel-1.3.4-13.3.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/libapr1-1.3.3-12.2.1.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/ppc/libapr1-devel-1.3.3-12.2.1.ppc.rpm
openSUSE 11.0:
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/apache2-2.2.8-28.8.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/apache2-devel-2.2.8-28.8.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/apache2-doc-2.2.8-28.8.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/apache2-example-pages-2.2.8-28.8.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/apache2-prefork-2.2.8-28.8.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/apache2-utils-2.2.8-28.8.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/apache2-worker-2.2.8-28.8.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr-util1-1.2.12-43.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr-util1-64bit-1.2.12-43.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr-util1-dbd-mysql-1.2.12-43.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr-util1-dbd-pgsql-1.2.12-43.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr-util1-dbd-sqlite3-1.2.12-43.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr-util1-devel-1.2.12-43.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr-util1-devel-64bit-1.2.12-43.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr1-1.2.12-27.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr1-64bit-1.2.12-27.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr1-devel-1.2.12-27.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/ppc/libapr1-devel-64bit-1.2.12-27.2.ppc.rpm
openSUSE 10.3:
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/apache2-2.2.4-70.11.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/apache2-devel-2.2.4-70.11.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/apache2-doc-2.2.4-70.11.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/apache2-example-pages-2.2.4-70.11.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/apache2-prefork-2.2.4-70.11.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/apache2-utils-2.2.4-70.11.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/apache2-worker-2.2.4-70.11.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr-util1-1.2.8-68.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr-util1-64bit-1.2.8-68.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr-util1-dbd-mysql-1.2.8-68.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr-util1-dbd-pgsql-1.2.8-68.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr-util1-dbd-sqlite3-1.2.8-68.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr-util1-devel-1.2.8-68.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr-util1-devel-64bit-1.2.8-68.4.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr1-1.2.9-9.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr1-64bit-1.2.9-9.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr1-devel-1.2.9-9.2.ppc.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/ppc/libapr1-devel-64bit-1.2.9-9.2.ppc.rpm
x86-64 Platform:
openSUSE 11.1:
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/x86_64/apache2-debuginfo-2.2.10-2.8.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/x86_64/apache2-debugsource-2.2.10-2.8.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/x86_64/libapr-util1-debuginfo-1.3.4-13.3.2.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/x86_64/libapr-util1-debugsource-1.3.4-13.3.2.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/x86_64/libapr1-debuginfo-1.3.3-12.2.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/debug/update/11.1/rpm/x86_64/libapr1-debugsource-1.3.3-12.2.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/apache2-2.2.10-2.8.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/apache2-devel-2.2.10-2.8.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/apache2-doc-2.2.10-2.8.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/apache2-example-pages-2.2.10-2.8.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/apache2-prefork-2.2.10-2.8.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/apache2-utils-2.2.10-2.8.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/apache2-worker-2.2.10-2.8.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/libapr-util1-1.3.4-13.3.2.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/libapr-util1-dbd-mysql-1.3.4-13.3.2.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/libapr-util1-dbd-pgsql-1.3.4-13.3.2.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/libapr-util1-dbd-sqlite3-1.3.4-13.3.2.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/libapr-util1-devel-1.3.4-13.3.2.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/libapr1-1.3.3-12.2.1.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/x86_64/libapr1-devel-1.3.3-12.2.1.x86_64.rpm
openSUSE 11.0:
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/apache2-2.2.8-28.8.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/apache2-devel-2.2.8-28.8.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/apache2-doc-2.2.8-28.8.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/apache2-example-pages-2.2.8-28.8.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/apache2-prefork-2.2.8-28.8.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/apache2-utils-2.2.8-28.8.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/apache2-worker-2.2.8-28.8.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/libapr-util1-1.2.12-43.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/libapr-util1-dbd-mysql-1.2.12-43.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/libapr-util1-dbd-pgsql-1.2.12-43.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/libapr-util1-dbd-sqlite3-1.2.12-43.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/libapr-util1-devel-1.2.12-43.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/libapr1-1.2.12-27.2.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/x86_64/libapr1-devel-1.2.12-27.2.x86_64.rpm
openSUSE 10.3:
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/apache2-2.2.4-70.11.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/apache2-devel-2.2.4-70.11.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/apache2-doc-2.2.4-70.11.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/apache2-example-pages-2.2.4-70.11.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/apache2-prefork-2.2.4-70.11.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/apache2-utils-2.2.4-70.11.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/apache2-worker-2.2.4-70.11.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/libapr-util1-1.2.8-68.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/libapr-util1-dbd-mysql-1.2.8-68.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/libapr-util1-dbd-pgsql-1.2.8-68.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/libapr-util1-dbd-sqlite3-1.2.8-68.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/libapr-util1-devel-1.2.8-68.4.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/libapr1-1.2.9-9.2.x86_64.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/x86_64/libapr1-devel-1.2.9-9.2.x86_64.rpm
Sources:
openSUSE 11.1:
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/src/libapr-util1-1.3.4-13.3.2.src.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/src/libapr1-1.3.3-12.2.1.src.rpm
openSUSE 11.0:
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/src/libapr-util1-1.2.12-43.4.src.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/src/libapr1-1.2.12-27.2.src.rpm
openSUSE 10.3:
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/src/apache2-2.2.4-70.11.src.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/src/libapr-util1-1.2.8-68.4.src.rpm
http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/src/libapr1-1.2.9-9.2.src.rpm
Our maintenance customers are notified individually. The packages are
offered for installation from the maintenance web:
SUSE Linux Enterprise Desktop 10 SP3
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=7d5c42318fd9b8e7c53cb5cebad8bffa
SUSE Linux Enterprise Desktop 10 SP2
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=756453d5faf1b9bc969224102bb99bd9
Open Enterprise Server
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=2fb3b9eca1524fb5f1da822967ea233e
Novell Linux POS 9
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=2fb3b9eca1524fb5f1da822967ea233e
Novell Linux Desktop 9
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=2fb3b9eca1524fb5f1da822967ea233e
SUSE SLES 9
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=2fb3b9eca1524fb5f1da822967ea233e
SLES 11
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=015ff2ecbdd9a5bbf220d3d2b1722666
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=ca7f5abf8025ba6ef69af14cd6570458
SLE 11
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=015ff2ecbdd9a5bbf220d3d2b1722666
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=ca7f5abf8025ba6ef69af14cd6570458
SLES 11 DEBUGINFO
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=015ff2ecbdd9a5bbf220d3d2b1722666
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=ca7f5abf8025ba6ef69af14cd6570458
SUSE Linux Enterprise Server 10 SP3
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=7d5c42318fd9b8e7c53cb5cebad8bffa
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=8de2d508793de8ff7df41d3b20495e54
SLE SDK 10 SP3
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=7d5c42318fd9b8e7c53cb5cebad8bffa
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=8de2d508793de8ff7df41d3b20495e54
SUSE Linux Enterprise 10 SP3 DEBUGINFO
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=8de2d508793de8ff7df41d3b20495e54
SUSE Linux Enterprise Server 10 SP2
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=756453d5faf1b9bc969224102bb99bd9
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=d5b711121aff7f0480198634eaa0003e
SLE SDK 10 SP2
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=756453d5faf1b9bc969224102bb99bd9
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=d5b711121aff7f0480198634eaa0003e
SUSE Linux Enterprise 10 SP2 DEBUGINFO
https://login.microfocus.com/nidp/idff/sso;set_restricted=true&keywords=d5b711121aff7f0480198634eaa0003e
______________________________________________________________________________
5) Pending Vulnerabilities, Solutions, and Work-Arounds:
See SUSE Security Summary Report.
______________________________________________________________________________
6) Authenticity Verification and Additional Information
- Announcement authenticity verification:
SUSE security announcements are published via mailing lists and on Web
sites. The authenticity and integrity of a SUSE security announcement is
guaranteed by a cryptographic signature in each announcement. All SUSE
security announcements are published with a valid signature.
To verify the signature of the announcement, save it as text into a file
and run the command
gpg --verify
replacing with the name of the file where you saved the
announcement. The output for a valid signature looks like:
gpg: Signature made using RSA key ID 3D25D3D9
gpg: Good signature from "SuSE Security Team "
where is replaced by the date the document was signed.
If the security team's key is not contained in your key ring, you can
import it from the first installation CD. To import the key, use the
command
gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc
- Package authenticity verification:
SUSE update packages are available on many mirror FTP servers all over the
world. While this service is considered valuable and important to the free
and open source software community, the authenticity and the integrity of
a package needs to be verified to ensure that it has not been tampered
with.
The internal rpm package signatures provide an easy way to verify the
authenticity of an RPM package. Use the command
rpm -v --checksig
to verify the signature of the package, replacing with the
filename of the RPM package downloaded. The package is unmodified if it
contains a valid signature from build@suse.de with the key ID 9C800ACA.
This key is automatically imported into the RPM database (on
RPMv4-based distributions) and the gpg key ring of 'root' during
installation. You can also find it on the first installation CD and at
the end of this announcement.
- SUSE runs two security mailing lists to which any interested party may
subscribe:
opensuse-security@opensuse.org
- General Linux and SUSE security discussion.
All SUSE security announcements are sent to this list.
To subscribe, send an e-mail to
.
opensuse-security-announce@opensuse.org
- SUSE's announce-only mailing list.
Only SUSE's security announcements are sent to this list.
To subscribe, send an e-mail to
.
==================================================================== SUSE's security contact is or .
The public key is listed below.
====================================================================