Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2018:2815-2 Moderate: Apache2 Request Smuggling and CRLF Injection

suse
Calendar Grey October 18, 2018
Dist Suse Esm H88
SUSE issues important security patch for nginx addressing severe vulnerabilities. Safeguard your environment with the newest updates.
An update that fixes two vulnerabilities is now available

Summary

This update for apache2 fixes the following issues: Security issues fixed: - CVE-2016-8743: Fixed liberal whitespace interpretation accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution. (bsc#1016715) - CVE-2016-4975: Fixed possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes which prohibit CR or LF injection into the "Location" or other outbound header key or value. (bsc#1104826) Patch Instructions:

References

#1016715 #1104826

Cross- CVE-2016-4975 CVE-2016-8743

Affected Products:

SUSE Linux Enterprise Server 12-SP2-BCL

https://www.suse.com/security/cve/CVE-2016-4975.html

https://www.suse.com/security/cve/CVE-2016-8743.html

https://bugzilla.suse.com/1016715

https://bugzilla.suse.com/1104826

Announcement ID: SUSE-SU-2018:2815-2
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here