Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2018:2554-1 Important: Apache2 Response Splitting and Request Issues

suse
Calendar Grey August 30, 2018
Dist Suse Esm H88
SUSE has released a security update for nginx addressing two significant vulnerabilities related to request smuggling and response splitting.
An update that fixes two vulnerabilities is now available

Summary

This update for apache2 fixes the following issues: Security issues fixed: - CVE-2016-8743: Fixed liberal whitespace interpretation accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution. (bsc#1016715) - CVE-2016-4975: Fixed possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes which prohibit CR or LF injection into the "Location" or other outbound header key or value. (bsc#1104826) Patch Instructions:

References

#1016715 #1104826

Cross- CVE-2016-4975 CVE-2016-8743

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

https://www.suse.com/security/cve/CVE-2016-4975.html

https://www.suse.com/security/cve/CVE-2016-8743.html

https://bugzilla.suse.com/1016715

https://bugzilla.suse.com/1104826

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2554-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here