Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2011:1000-1 Critical: Apache Remote Denial of Service Patch

suse
Calendar Grey September 6, 2011
Dist Suse Esm H88
Address significant Apache security flaws for SUSE Linux Enterprise. Upgrade immediately for improved protection.
An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now...

Summary


Warning: Undefined array key "advisoryid" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4180758_1edcd913e2b52798c5b9126b8927230e on line 19

   SUSE Security Update: Security update for Apache
______________________________________________________________________________

Announcement ID:    SUSE-SU-2011:1000-1
Rating:             important
References:         #627030 #670027 #690734 #696251 #713966 
Cross-References:   CVE-2010-1452 CVE-2011-3192
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP1
                    SUSE Linux Enterprise Server 11 SP1 for VMware
                    SUSE Linux Enterprise Server 11 SP1
______________________________________________________________________________

   An update that solves two vulnerabilities and has three
   fixes is now available.

Description:


   This update fixes a remote denial of service bug (memory
   exhaustion) in the  Apache 2 HTTP server, that could be
   triggered by remote attackers using  multiple overlapping
   Request Ranges. (CVE-2011-3192)

   It also fixes a issue in mod_dav, where the (1) mod_cache
   and (2) mod_dav  modules in the Apache HTTP Server 2.2.x
   allowed remote attackers to cause a  denial of service
   (process crash) via a request that lacks a path.
   (CVE-2010-1452)

   Also following bugs were fixed:

   * recommend the default MPM (prefork) via Recommends:
   in .spec
   * apache not sending error 304 if mod_deflate is
   enabled.
   * take LimitRequestFieldsize config option into account
   when parsing headers from backend.

   Security Issue references:

   * CVE-2011-3192
   
   * CVE-2010-1452
   

Indications:

   Please install this update.

Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP1:

      zypper in -t patch sdksp1-apache2-5090

   - SUSE Linux Enterprise Server 11 SP1 for VMware:

      zypper in -t patch slessp1-apache2-5090

   - SUSE Linux Enterprise Server 11 SP1:

      zypper in -t patch slessp1-apache2-5090

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP1 (i586 ia64 ppc64 s390x x86_64):

      apache2-devel-2.2.10-2.30.1

   - SUSE Linux Enterprise Software Development Kit 11 SP1 (i586 x86_64):

      apache2-2.2.10-2.30.1
      apache2-doc-2.2.10-2.30.1
      apache2-example-pages-2.2.10-2.30.1
      apache2-prefork-2.2.10-2.30.1
      apache2-utils-2.2.10-2.30.1
      apache2-worker-2.2.10-2.30.1

   - SUSE Linux Enterprise Server 11 SP1 for VMware (i586 x86_64):

      apache2-2.2.10-2.30.1
      apache2-doc-2.2.10-2.30.1
      apache2-example-pages-2.2.10-2.30.1
      apache2-prefork-2.2.10-2.30.1
      apache2-utils-2.2.10-2.30.1
      apache2-worker-2.2.10-2.30.1

   - SUSE Linux Enterprise Server 11 SP1 (i586 ia64 ppc64 s390x x86_64):

      apache2-2.2.10-2.30.1
      apache2-doc-2.2.10-2.30.1
      apache2-example-pages-2.2.10-2.30.1
      apache2-prefork-2.2.10-2.30.1
      apache2-utils-2.2.10-2.30.1
      apache2-worker-2.2.10-2.30.1


References:

   https://www.suse.com/security/cve/CVE-2010-1452.html
   https://www.suse.com/security/cve/CVE-2011-3192.html
   
   
   
   
   
   

References

Severity
critical
Lowest
Low
Medium
High
Critical


Warning: Undefined array key "block1" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4180758_c1d2d4f425d79c8c327f2b8603847ec6 on line 11

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here