SuSE: 2012:1156-2: important: PHP5
Summary
This update fixes CVE-2011-1398 and CVE-2011-4388 (header
injection via CR).
This update also changes the default configuration to use
FilesMatch with 'SetHandler' rather than 'AddHandler' to
protect weakly written web applications from content
confusion. Since this is a hardening measure, no CVE was
assigned.
Security Issue references:
* CVE-2011-1398
References
#775852 #778003
Cross- CVE-2011-1398 CVE-2011-4388
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Linux Enterprise Server 11 SP2 for VMware
SUSE Linux Enterprise Server 11 SP2
https://www.suse.com/security/cve/CVE-2011-1398.html
https://www.suse.com/security/cve/CVE-2011-4388.html
https://bugzilla.novell.com/775852
https://bugzilla.novell.com/778003
https://login.microfocus.com/nidp/app/login