SUSE Security Update: Security update for Apache
______________________________________________________________________________

Announcement ID:    SUSE-SU-2011:1000-1
Rating:             important
References:         #627030 #670027 #690734 #696251 #713966 
Cross-References:   CVE-2010-1452 CVE-2011-3192
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP1
                    SUSE Linux Enterprise Server 11 SP1 for VMware
                    SUSE Linux Enterprise Server 11 SP1
______________________________________________________________________________

   An update that solves two vulnerabilities and has three
   fixes is now available.

Description:


   This update fixes a remote denial of service bug (memory
   exhaustion) in the  Apache 2 HTTP server, that could be
   triggered by remote attackers using  multiple overlapping
   Request Ranges. (CVE-2011-3192)

   It also fixes a issue in mod_dav, where the (1) mod_cache
   and (2) mod_dav  modules in the Apache HTTP Server 2.2.x
   allowed remote attackers to cause a  denial of service
   (process crash) via a request that lacks a path.
   (CVE-2010-1452)

   Also following bugs were fixed:

   * recommend the default MPM (prefork) via Recommends:
   in .spec
   * apache not sending error 304 if mod_deflate is
   enabled.
   * take LimitRequestFieldsize config option into account
   when parsing headers from backend.

   Security Issue references:

   * CVE-2011-3192
   
   * CVE-2010-1452
   

Indications:

   Please install this update.

Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP1:

      zypper in -t patch sdksp1-apache2-5090

   - SUSE Linux Enterprise Server 11 SP1 for VMware:

      zypper in -t patch slessp1-apache2-5090

   - SUSE Linux Enterprise Server 11 SP1:

      zypper in -t patch slessp1-apache2-5090

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP1 (i586 ia64 ppc64 s390x x86_64):

      apache2-devel-2.2.10-2.30.1

   - SUSE Linux Enterprise Software Development Kit 11 SP1 (i586 x86_64):

      apache2-2.2.10-2.30.1
      apache2-doc-2.2.10-2.30.1
      apache2-example-pages-2.2.10-2.30.1
      apache2-prefork-2.2.10-2.30.1
      apache2-utils-2.2.10-2.30.1
      apache2-worker-2.2.10-2.30.1

   - SUSE Linux Enterprise Server 11 SP1 for VMware (i586 x86_64):

      apache2-2.2.10-2.30.1
      apache2-doc-2.2.10-2.30.1
      apache2-example-pages-2.2.10-2.30.1
      apache2-prefork-2.2.10-2.30.1
      apache2-utils-2.2.10-2.30.1
      apache2-worker-2.2.10-2.30.1

   - SUSE Linux Enterprise Server 11 SP1 (i586 ia64 ppc64 s390x x86_64):

      apache2-2.2.10-2.30.1
      apache2-doc-2.2.10-2.30.1
      apache2-example-pages-2.2.10-2.30.1
      apache2-prefork-2.2.10-2.30.1
      apache2-utils-2.2.10-2.30.1
      apache2-worker-2.2.10-2.30.1


References:

   https://www.suse.com/security/cve/CVE-2010-1452.html
   https://www.suse.com/security/cve/CVE-2011-3192.html
   https://bugzilla.novell.com/627030
   https://bugzilla.novell.com/670027
   https://bugzilla.novell.com/690734
   https://bugzilla.novell.com/696251
   https://bugzilla.novell.com/713966
   https://login.microfocus.com/nidp/app/login

SuSE: 2011:1000-1: important: Apache

September 6, 2011
An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now...

Summary

   SUSE Security Update: Security update for Apache
______________________________________________________________________________

Announcement ID:    SUSE-SU-2011:1000-1
Rating:             important
References:         #627030 #670027 #690734 #696251 #713966 
Cross-References:   CVE-2010-1452 CVE-2011-3192
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP1
                    SUSE Linux Enterprise Server 11 SP1 for VMware
                    SUSE Linux Enterprise Server 11 SP1
______________________________________________________________________________

   An update that solves two vulnerabilities and has three
   fixes is now available.

Description:


   This update fixes a remote denial of service bug (memory
   exhaustion) in the  Apache 2 HTTP server, that could be
   triggered by remote attackers using  multiple overlapping
   Request Ranges. (CVE-2011-3192)

   It also fixes a issue in mod_dav, where the (1) mod_cache
   and (2) mod_dav  modules in the Apache HTTP Server 2.2.x
   allowed remote attackers to cause a  denial of service
   (process crash) via a request that lacks a path.
   (CVE-2010-1452)

   Also following bugs were fixed:

   * recommend the default MPM (prefork) via Recommends:
   in .spec
   * apache not sending error 304 if mod_deflate is
   enabled.
   * take LimitRequestFieldsize config option into account
   when parsing headers from backend.

   Security Issue references:

   * CVE-2011-3192
   
   * CVE-2010-1452
   

Indications:

   Please install this update.

Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP1:

      zypper in -t patch sdksp1-apache2-5090

   - SUSE Linux Enterprise Server 11 SP1 for VMware:

      zypper in -t patch slessp1-apache2-5090

   - SUSE Linux Enterprise Server 11 SP1:

      zypper in -t patch slessp1-apache2-5090

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP1 (i586 ia64 ppc64 s390x x86_64):

      apache2-devel-2.2.10-2.30.1

   - SUSE Linux Enterprise Software Development Kit 11 SP1 (i586 x86_64):

      apache2-2.2.10-2.30.1
      apache2-doc-2.2.10-2.30.1
      apache2-example-pages-2.2.10-2.30.1
      apache2-prefork-2.2.10-2.30.1
      apache2-utils-2.2.10-2.30.1
      apache2-worker-2.2.10-2.30.1

   - SUSE Linux Enterprise Server 11 SP1 for VMware (i586 x86_64):

      apache2-2.2.10-2.30.1
      apache2-doc-2.2.10-2.30.1
      apache2-example-pages-2.2.10-2.30.1
      apache2-prefork-2.2.10-2.30.1
      apache2-utils-2.2.10-2.30.1
      apache2-worker-2.2.10-2.30.1

   - SUSE Linux Enterprise Server 11 SP1 (i586 ia64 ppc64 s390x x86_64):

      apache2-2.2.10-2.30.1
      apache2-doc-2.2.10-2.30.1
      apache2-example-pages-2.2.10-2.30.1
      apache2-prefork-2.2.10-2.30.1
      apache2-utils-2.2.10-2.30.1
      apache2-worker-2.2.10-2.30.1


References:

   https://www.suse.com/security/cve/CVE-2010-1452.html
   https://www.suse.com/security/cve/CVE-2011-3192.html
   https://bugzilla.novell.com/627030
   https://bugzilla.novell.com/670027
   https://bugzilla.novell.com/690734
   https://bugzilla.novell.com/696251
   https://bugzilla.novell.com/713966
   https://login.microfocus.com/nidp/app/login

References

Severity

Related News