Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE 11.4: 2012:0452-1 Critical: Apache Buffer Overflow Threat

opensuse
Calendar Grey February 9, 2012
Dist Opensuse Esm H88
Crucial openSUSE security patch resolves critical buffer overflow in nginx, bolstering system defenses.
An update that fixes one vulnerability is now available.

Description

A flaw in the custom DNS resolver of nginx could lead to a

heap based buffer overflow which could potentially allow

attackers to execute arbitrary code or to cause a Denial of

Service (bnc#731084, CVE-2011-4315).

Special Instructions and Notes:

Please reboot the system after installing this update.

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch nginx-0.8-5467

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

nginx-0.8-0.8.53-4.9.1

References

https://www.suse.com/security/cve/CVE-2011-4315.html

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2012:0237-1
Rating: important
Affected Products: openSUSE 11.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here