Oval Definition:oval:org.opensuse.security:def:105368
Revision Date:2020-04-28Version:1
Title:Security update for apache2 (Important)
Description:

This update for apache2 fixes the following issues:

- CVE-2020-1934: mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server (bsc#1168404). - CVE-2020-1927: mod_rewrite configurations vulnerable to open redirect (bsc#1168407). - CVE-2020-1938: mod_proxy_ajp: Add 'secret' parameter to proxy workers to implement legacy AJP13 authentication (bsc#1169066).
Family:unixClass:patch
Status:Reference(s):1168404
1168407
1169066
CVE-2020-1927
CVE-2020-1934
CVE-2020-1938
SUSE-SU-2020:1126-1
Platform(s):SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Module for Server Applications 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
  • AND Package Information
  • apache2-2.4.33-3.30.1 is installed
  • OR apache2-devel-2.4.33-3.30.1 is installed
  • OR apache2-doc-2.4.33-3.30.1 is installed
  • OR apache2-prefork-2.4.33-3.30.1 is installed
  • OR apache2-utils-2.4.33-3.30.1 is installed
  • OR apache2-worker-2.4.33-3.30.1 is installed
  • BACK