Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2018:2815-1 Moderate: Apache2 Request Smuggling & Response Splitting

suse
Calendar Grey September 24, 2018
Dist Suse Esm H88
SUSE Security Notice: Addresses issues in nginx, enhancing web server protection. Ensure your environments are updated to reduce potential threats.
An update that fixes two vulnerabilities is now available

Summary

This update for apache2 fixes the following issues: Security issues fixed: - CVE-2016-8743: Fixed liberal whitespace interpretation accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution. (bsc#1016715) - CVE-2016-4975: Fixed possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes which prohibit CR or LF injection into the "Location" or other outbound header key or value. (bsc#1104826) Patch Instructions:

References

#1016715 #1104826

Cross- CVE-2016-4975 CVE-2016-8743

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Enterprise Storage 4

https://www.suse.com/security/cve/CVE-2016-4975.html

https://www.suse.com/security/cve/CVE-2016-8743.html

https://bugzilla.suse.com/1016715

https://bugzilla.suse.com/1104826

Announcement ID: SUSE-SU-2018:2815-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here