Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 481
Alerts This Week
Warning Icon 1 481

SUSE: 2013:1667-1 Important: apache2-mod_fcgid Heap Overflow

suse
Calendar Grey November 13, 2013
Scroller Suse
A critical patch has been released for apache2-mod_fcgid, resolving a heap overflow vulnerability present in SUSE Linux systems.
An update that fixes one vulnerability is now available

Summary

A heap overflow in the apache2-mod_fcgid module has been fixed that could have been used by remote attackers to crash the server instance. (CVE-2013-4365) Security Issue reference: * CVE-2013-4365 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP3: zypper in -t patch sdksp3-apache2-mod_fcgid-8507 - SUSE Linux Enterprise Software Development Kit 11 SP2: zypper in -t patch sdksp2-apache2-mod_fcgid-8513 - SUSE Cloud 2.0: zypper in -t patch sleclo20sp3-apache2-mod_fcgid-8507 - SUSE Cloud 1.0: zypper in -t patch sleclo10sp2-apache2-mod_fcgid-8513

References

#844935

Cross- CVE-2013-4365

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Cloud 2.0

SUSE Cloud 1.0

https://www.suse.com/security/cve/CVE-2013-4365.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:1667-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.