Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2019:2329-1 Important: Apache2 Security Issues Resolved

suse
Calendar Grey September 6, 2019
Dist Suse Esm H88
Addresses critical vulnerabilities in apache2 relevant to SUSE Linux Enterprise Server. Apply essential updates to safeguard your environment.
An update that fixes 5 vulnerabilities is now available

Summary

This update for apache2 fixes the following issues: Security issues fixed: - CVE-2019-9517: Fixed HTTP/2 implementations that are vulnerable to unconstrained interal data buffering (bsc#1145575). - CVE-2019-10081: Fixed mod_http2 that is vulnerable to memory corruption on early pushes (bsc#1145742). - CVE-2019-10082: Fixed mod_http2 that is vulnerable to read-after-free in h2 connection shutdown (bsc#1145741). - CVE-2019-10092: Fixed limited cross-site scripting in mod_proxy (bsc#1145740). - CVE-2019-10098: Fixed mod_rewrite configuration vulnerablility to open redirect (bsc#1145738). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1145575 #1145738 #1145740 #1145741 #1145742

Cross- CVE-2019-10081 CVE-2019-10082 CVE-2019-10092

CVE-2019-10098 CVE-2019-9517

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Server 12-SP4

https://www.suse.com/security/cve/CVE-2019-10081.html

https://www.suse.com/security/cve/CVE-2019-10082.html

https://www.suse.com/security/cve/CVE-2019-10092.html

https://www.suse.com/security/cve/CVE-2019-10098.html

https://www.suse.com/security/cve/CVE-2019-9517.html

https://bugzilla.suse.com/1145575

https://bugzilla.suse.com/1145738

https://bugzilla.suse.com/1145740

https://bugzilla.suse.com/1145741

https://bugzilla.suse.com/1145742

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2329-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here