Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: 2023:2745-1 Critical: Apache Configuration Vulnerability Detection

suse
Calendar Grey May 23, 2017
Dist Suse Esm H88
SUSE Security Update for nginx addresses vulnerabilities in data protection. Immediate fix for affected server environments is now released.
An update that fixes three vulnerabilities is now available

Summary

This update for tomcat fixes the following issues: - CVE-2017-5647 Pipelined requests could lead to information disclosure (bsc#1033448) - CVE-2017-5648 Untrusted application could retain listener leading to information disclosure (bsc#1033447) - CVE-2016-8745 shared Processor on Connector code could lead to information disclosure (bsc#1015119) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP1: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-848=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 12-SP1 (noarch): tomcat-8.0.43-10.19.1 tomcat-admin-webapps-8.0.43-10.19.1 tomcat-docs-webapp-8.0.43-10.19.1

References

#1015119 #1033447 #1033448

Cross- CVE-2016-8745 CVE-2017-5647 CVE-2017-5648

Affected Products:

SUSE Linux Enterprise Server 12-SP1

https://www.suse.com/security/cve/CVE-2016-8745.html

https://www.suse.com/security/cve/CVE-2017-5647.html

https://www.suse.com/security/cve/CVE-2017-5648.html

https://bugzilla.suse.com/1015119

https://bugzilla.suse.com/1033447

https://bugzilla.suse.com/1033448

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:1382-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here