Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 481
Alerts This Week
Warning Icon 1 481

SUSE: 2014:1081-1 Important: Apache2 Denial Of Service Fixes

suse
Calendar Grey September 2, 2014
Scroller Suse
Essential SUSE Security Patch tackling various vulnerabilities in apache2. Update can be installed right away.
An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two fixes is now av...

Summary

This apache2 update fixes the following security and non-security issues: * mod_cgid denial of service (CVE-2014-0231, bnc#887768) * mod_status heap-based buffer overflow (CVE-2014-0226, bnc#887765) * mod_dav denial of service (CVE-2013-6438, bnc#869105) * log_cookie mod_log_config.c remote denial of service (CVE-2014-0098, bnc#869106) * Support ECDH in Apache2 (bnc#859916) * apache fails to start with SSL on Xen kernel at boot time (bnc#852401) Security Issues: * CVE-2014-0098 * CVE-2013-6438 * CVE-2014-0226 * CVE-2014-0231

References

#852401 #859916 #869105 #869106 #887765 #887768

Cross- CVE-2013-6438 CVE-2014-0098 CVE-2014-0226

CVE-2014-0231

Affected Products:

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2013-6438.html

https://www.suse.com/security/cve/CVE-2014-0098.html

https://www.suse.com/security/cve/CVE-2014-0226.html

https://www.suse.com/security/cve/CVE-2014-0231.html

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1081-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.