Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2020:1171-1 Moderate: nginx HTTP Request Smuggling Fix

suse
Calendar Grey May 4, 2020
Dist Suse Esm H88
The latest patch addresses a vulnerability in Apache, improving both security measures and overall performance in Red Hat systems.
An update that solves one vulnerability and has three fixes is now available

Summary

This update for nginx fixes the following issues: nginx was updated to 1.16.1 (jsc#ECO-1401) - Added TLS 1.3 support (jsc#SLE-9295, bsc#1150711) - Replaced obsolete GeoIP module with MaxMinDB-based GeoIP2 (jsc#SLE-11184, bsc#1156202) - Started nginx after network is online (bsc#1155690) - CVE-2019-20372: Fixed an HTTP request smuggling with certain error_page configurations which could have allowed unauthorized web page reads (bsc#1160682). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2020-1171=1 - SUSE Linux Enterprise Server 15-LTSS:

References

#1150711 #1155690 #1156202 #1160682

Cross- CVE-2019-20372

Affected Products:

SUSE Linux Enterprise Server for SAP 15

SUSE Linux Enterprise Server 15-LTSS

SUSE Linux Enterprise High Performance Computing 15-LTSS

SUSE Linux Enterprise High Performance Computing 15-ESPOS

https://www.suse.com/security/cve/CVE-2019-20372.html

https://bugzilla.suse.com/1150711

https://bugzilla.suse.com/1155690

https://bugzilla.suse.com/1156202

https://bugzilla.suse.com/1160682

Announcement ID: SUSE-SU-2020:1171-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here