Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE: 2011:1216-1 Important: Apache 2 Denial of Service Fix

suse
Calendar Grey November 4, 2011
Dist Suse Esm H88
Critical patch released for Apache 2 on SUSE, mitigating a denial of service vulnerability and additional concerns.
An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is now...

Summary


Warning: Undefined array key "advisoryid" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4094014_1edcd913e2b52798c5b9126b8927230e on line 19

   SUSE Security Update: Security update for Apache 2
______________________________________________________________________________

Announcement ID:    SUSE-SU-2011:1216-1
Rating:             important
References:         #555098 #627030 #661597 #663359 #690734 #713966 
                    
Cross-References:   CVE-2011-3192
Affected Products:
                    SUSE Linux Enterprise Server 10 SP2
______________________________________________________________________________

   An update that solves one vulnerability and has 5 fixes is
   now available.

Description:


   This update fixes a remote denial of service bug (memory
   exhaustion) in the  Apache 2 HTTP server, that could be
   triggered by remote attackers using  multiple overlapping
   Request Ranges . (CVE-2011-3192)

   The fix introduces a new config option: Allow MaxRanges
   Number of ranges requested, if exceeded, the complete
   content is served. default: 200 0|unlimited: unlimited
   none: Range headers are ignored. (This option is a backport
   from 2.2.21.)

   It fixes also the minor security issue in the mod_cache
   modules in the  Apache HTTP Server that allowed remote
   attackers to cause a denial of  service (process crash) via
   a request that lacks a path. (CVE-2010-1452)

   It also fixes some non-security bugs: - take
   LimitRequestFieldsize config  option into account when
   parsing headers from backend. Thereby avoid that  the
   receiving buffers are too small. bnc#690734. - add / when
   on a  directory to feed correctly linked listings.
   bnc#661597 - a2enmod shalt not  disable a module in query
   mode. bnc#663359 - New option SSLRenegBufferSize  fixes
   "413 Request Entity Too Large occur" problem. - fixes
   graceful  restart hangs, bnc#555098.

   Security Issues:

   * CVE-2011-3192
   

Indications:

   Please install this update.


Package List:

   - SUSE Linux Enterprise Server 10 SP2 (i586 s390x x86_64):

      apache2-2.2.3-16.25.40
      apache2-devel-2.2.3-16.25.40
      apache2-doc-2.2.3-16.25.40
      apache2-example-pages-2.2.3-16.25.40
      apache2-prefork-2.2.3-16.25.40
      apache2-worker-2.2.3-16.25.40


References:

   https://www.suse.com/security/cve/CVE-2011-3192.html
   
   
   
   
   
   
   

References

Severity
important
Lowest
Low
Medium
High
Critical


Warning: Undefined array key "block1" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4094014_c1d2d4f425d79c8c327f2b8603847ec6 on line 11

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here