Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE Linux Enterprise Server: 2011:1007-1 Critical: Apache Remote DoS

suse
Calendar Grey September 6, 2011
Scroller Suse
SUSE releases critical security patch for Apache, resolving a significant remote denial-of-service vulnerability. Update now available.
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is ...

Summary

   SUSE Security Update: Security update for Apache
______________________________________________________________________________

Announcement ID:    SUSE-SU-2011:1007-1
Rating:             important
References:         #690734 #713966 
Cross-References:   CVE-2011-3192
Affected Products:
                    SUSE Linux Enterprise Server 10 SP4
                    SLE SDK 10 SP4
______________________________________________________________________________

   An update that solves one vulnerability and has one errata
   is now available.

Description:


   This update fixes a remote denial of service bug (memory
   exhaustion) in the  Apache 2 HTTP server, that could be
   triggered by remote attackers using  multiple overlapping
   Request Ranges. (CVE-2011-3192)

   It also fixes a bug, where the LimitRequestFieldsize config
   option into  account when parsing headers from backend,
   thereby avoiding that the  receiving buffers are too small.

   Security Issue reference:

   * CVE-2011-3192
   

Indications:

   Please install this update.


Package List:

   - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64):

      apache2-2.2.3-16.36.1
      apache2-devel-2.2.3-16.36.1
      apache2-doc-2.2.3-16.36.1
      apache2-example-pages-2.2.3-16.36.1
      apache2-prefork-2.2.3-16.36.1
      apache2-worker-2.2.3-16.36.1

   - SLE SDK 10 SP4 (i586 ia64 ppc s390x x86_64):

      apache2-2.2.3-16.36.1
      apache2-devel-2.2.3-16.36.1
      apache2-doc-2.2.3-16.36.1
      apache2-example-pages-2.2.3-16.36.1
      apache2-prefork-2.2.3-16.36.1
      apache2-worker-2.2.3-16.36.1


References:

   https://www.suse.com/security/cve/CVE-2011-3192.html
   
   
   

References

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.