Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE: 2019:2549-1 Moderate: apache2-mod_perl Code Execution Risk

opensuse
Calendar Grey November 23, 2019
Dist Opensuse Esm H88
The recent security patch for apache2-mod_perl on openSUSE resolves a code execution vulnerability that has been classified as having moderate risk.
An update that solves one vulnerability and has one errata is now available.

Description

This update for apache2-mod_perl to version 2.0.11 fixes the following

issues:

Security issue fixed:

- CVE-2011-2767: Fixed a vulnerability which could have allowed perl code

execution in the context of user account (bsc#1156944).

Other issue addressed:

- Restore process name after sv_setpv_mg() call. (bsc#1091625)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2019-2549=1

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-2549=1

Package List

- openSUSE Leap 15.1 (x86_64):

apache2-mod_perl-2.0.11-lp151.3.3.1

apache2-mod_perl-debuginfo-2.0.11-lp151.3.3.1

apache2-mod_perl-debugsource-2.0.11-lp151.3.3.1

apache2-mod_perl-devel-2.0.11-lp151.3.3.1

- openSUSE Leap 15.0 (x86_64):

apache2-mod_perl-2.0.11-lp150.2.3.1

apache2-mod_perl-debuginfo-2.0.11-lp150.2.3.1

apache2-mod_perl-debugsource-2.0.11-lp150.2.3.1

apache2-mod_perl-devel-2.0.11-lp150.2.3.1

References

https://www.suse.com/security/cve/CVE-2011-2767.html

https://bugzilla.suse.com/1091625

https://bugzilla.suse.com/1156944

--

Announcement ID: openSUSE-SU-2019:2549-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here