Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE Linux 10 SP3: 2011:1010-1 Critical: Apache Memory Exhaustion

suse
Calendar Grey September 6, 2011
Dist Suse Esm H88
Crucial patch from SUSE for Apache resolves a critical memory overflow flaw and includes further enhancements for improved stability.
An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is ...

Summary


Warning: Undefined array key "advisoryid" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/107339_1edcd913e2b52798c5b9126b8927230e on line 19

   SUSE Security Update: Security update for Apache
______________________________________________________________________________

Announcement ID:    SUSE-SU-2011:1010-1
Rating:             important
References:         #555098 #661597 #663359 #690734 #713966 
Cross-References:   CVE-2011-3192
Affected Products:
                    SUSE Linux Enterprise Server 10 SP3
                    SLE SDK 10 SP3
______________________________________________________________________________

   An update that solves one vulnerability and has four fixes
   is now available.

Description:


   This update fixes a remote denial of service bug (memory
   exhaustion) in the  Apache 2 HTTP server, that could be
   triggered by remote attackers using  multiple overlapping
   Request Ranges. (CVE-2011-3192)

   It also fixes some non-security bugs:

   * take LimitRequestFieldsize config option into account
   when parsing headers from backend. Thereby avoid that the
   receiving buffers are too small. bnc#690734.
   * add / when on a directory to feed correctly linked
   listings. bnc#661597
   * a2enmod shalt not disable a module in query mode.
   bnc#663359
   * New option SSLRenegBufferSize fixes "413 Request
   Entity Too Large occur" problem.
   * fixes graceful restart hangs, bnc#555098.

   Security Issue reference:

   * CVE-2011-3192
   

Indications:

   Please install this update.


Package List:

   - SUSE Linux Enterprise Server 10 SP3 (i586 ia64 ppc s390x x86_64):

      apache2-2.2.3-16.32.35.1
      apache2-devel-2.2.3-16.32.35.1
      apache2-doc-2.2.3-16.32.35.1
      apache2-example-pages-2.2.3-16.32.35.1
      apache2-prefork-2.2.3-16.32.35.1
      apache2-worker-2.2.3-16.32.35.1

   - SLE SDK 10 SP3 (i586 ia64 ppc s390x x86_64):

      apache2-2.2.3-16.32.35.1
      apache2-devel-2.2.3-16.32.35.1
      apache2-doc-2.2.3-16.32.35.1
      apache2-example-pages-2.2.3-16.32.35.1
      apache2-prefork-2.2.3-16.32.35.1
      apache2-worker-2.2.3-16.32.35.1


References:

   https://www.suse.com/security/cve/CVE-2011-3192.html
   
   
   
   
   
   

References

Severity
important
Lowest
Low
Medium
High
Critical


Warning: Undefined array key "block1" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/107339_c1d2d4f425d79c8c327f2b8603847ec6 on line 11

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here