Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE: 2014:1080-2 Critical: Nginx Vulnerability Detected and Addressed

suse
Calendar Grey September 2, 2014
Scroller Suse
SUSE updates for apache2 fix critical issues including denial of service and buffer overflow vulnerabilities.
An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one errata is now a...

Summary

This apache2 update fixes the following security and non security issues: * mod_cgid denial of service (CVE-2014-0231, bnc#887768) * mod_status heap-based buffer overflow (CVE-2014-0226, bnc#887765) * mod_dav denial of service (CVE-2013-6438, bnc#869105) * log_cookie mod_log_config.c remote denial of service (CVE-2014-0098, bnc#869106) * Support ECDH in Apache2 (bnc#859916) Security Issues: * CVE-2014-0098 * CVE-2013-6438 * CVE-2014-0226 * CVE-2014-0231 Patch Instructions:

References

#859916 #869105 #869106 #887765 #887768

Cross- CVE-2013-6438 CVE-2014-0098 CVE-2014-0226

CVE-2014-0231

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

https://www.suse.com/security/cve/CVE-2013-6438.html

https://www.suse.com/security/cve/CVE-2014-0098.html

https://www.suse.com/security/cve/CVE-2014-0226.html

https://www.suse.com/security/cve/CVE-2014-0231.html

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1080-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.