SUSE Security Update: Security update for apache2
______________________________________________________________________________

Announcement ID:    SUSE-SU-2014:1080-1
Rating:             important
References:         #859916 #869105 #869106 #887765 #887768 
Cross-References:   CVE-2013-6438 CVE-2014-0098 CVE-2014-0226
                    CVE-2014-0231
Affected Products:
                    SUSE Linux Enterprise Server 11 SP2 LTSS
______________________________________________________________________________

   An update that solves four vulnerabilities and has one
   errata is now available.

Description:


   This apache2 update fixes the following security and non security issues:

       * mod_cgid denial of service (CVE-2014-0231, bnc#887768)
       * mod_status heap-based buffer overflow (CVE-2014-0226, bnc#887765)
       * mod_dav denial of service (CVE-2013-6438, bnc#869105)
       * log_cookie mod_log_config.c remote denial of service (CVE-2014-0098,
         bnc#869106)
       * Support ECDH in Apache2 (bnc#859916)

   Security Issues:

       * CVE-2014-0098
         
       * CVE-2013-6438
         
       * CVE-2014-0226
         
       * CVE-2014-0231
         


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Server 11 SP2 LTSS:

      zypper in -t patch slessp2-apache2-9620

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Server 11 SP2 LTSS (i586 s390x x86_64):

      apache2-2.2.12-1.48.1
      apache2-doc-2.2.12-1.48.1
      apache2-example-pages-2.2.12-1.48.1
      apache2-prefork-2.2.12-1.48.1
      apache2-utils-2.2.12-1.48.1
      apache2-worker-2.2.12-1.48.1


References:

   https://www.suse.com/security/cve/CVE-2013-6438.html
   https://www.suse.com/security/cve/CVE-2014-0098.html
   https://www.suse.com/security/cve/CVE-2014-0226.html
   https://www.suse.com/security/cve/CVE-2014-0231.html
   https://bugzilla.novell.com/859916
   https://bugzilla.novell.com/869105
   https://bugzilla.novell.com/869106
   https://bugzilla.novell.com/887765
   https://bugzilla.novell.com/887768
   https://scc.suse.com:443/patches/

SuSE: 2014:1080-1: important: apache2

September 2, 2014
An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one errata is now a...

Summary

This apache2 update fixes the following security and non security issues: * mod_cgid denial of service (CVE-2014-0231, bnc#887768) * mod_status heap-based buffer overflow (CVE-2014-0226, bnc#887765) * mod_dav denial of service (CVE-2013-6438, bnc#869105) * log_cookie mod_log_config.c remote denial of service (CVE-2014-0098, bnc#869106) * Support ECDH in Apache2 (bnc#859916) Security Issues: * CVE-2014-0098 * CVE-2013-6438 * CVE-2014-0226 * CVE-2014-0231 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP2 LTSS: zypper in -t patch slessp2-apache2-9620 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP2 LTSS (i586 s390x x86_64): apache2-2.2.12-1.48.1 ...

Read the Full Advisory

References

#859916 #869105 #869106 #887765 #887768

Cross- CVE-2013-6438 CVE-2014-0098 CVE-2014-0226

CVE-2014-0231

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

https://www.suse.com/security/cve/CVE-2013-6438.html

https://www.suse.com/security/cve/CVE-2014-0098.html

https://www.suse.com/security/cve/CVE-2014-0226.html

https://www.suse.com/security/cve/CVE-2014-0231.html

https://bugzilla.novell.com/859916

https://bugzilla.novell.com/869105

https://bugzilla.novell.com/869106

https://bugzilla.novell.com/887765

https://bugzilla.novell.com/887768

https://scc.suse.com:443/patches/

Severity
Announcement ID: SUSE-SU-2014:1080-1
Rating: important

Related News