Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

SUSE Linux 10 SP4: 2014:1082-1 Important: Apache2 Service Fix

suse
Calendar Grey September 2, 2014
Scroller Suse
SUSE update for apache2 addresses multiple issues, including denial of service and buffer overflow risks in the system.
An update that fixes 6 vulnerabilities is now available

Summary

This apache2 update fixes the following security issues: * log_cookie mod_log_config.c remote denial of service (CVE-2014-0098, bnc#869106) * mod_dav denial of service (CVE-2013-6438, bnc#869105) * mod_cgid denial of service (CVE-2014-0231, bnc#887768) * mod_status heap-based buffer overflow (CVE-2014-0226, bnc#887765) * mod_rewrite: escape logdata to avoid terminal escapes (CVE-2013-1862, bnc#829057) * mod_dav: segfault in merge request (CVE-2013-1896, bnc#829056) Security Issues: * CVE-2014-0098 * CVE-2013-6438 * CVE-2014-0226 * CVE-2014-0231

References

#829056 #829057 #869105 #869106 #887765 #887768

Cross- CVE-2013-1862 CVE-2013-1896 CVE-2013-6438

CVE-2014-0098 CVE-2014-0226 CVE-2014-0231

Affected Products:

SUSE Linux Enterprise Server 10 SP4 LTSS

SUSE Linux Enterprise Server 10 SP3 LTSS

https://www.suse.com/security/cve/CVE-2013-1862.html

https://www.suse.com/security/cve/CVE-2013-1896.html

https://www.suse.com/security/cve/CVE-2013-6438.html

https://www.suse.com/security/cve/CVE-2014-0098.html

https://www.suse.com/security/cve/CVE-2014-0226.html

https://www.suse.com/security/cve/CVE-2014-0231.html

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1082-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.