Oval Definition:oval:org.opensuse.security:def:109971
Revision Date:2019-09-02Version:1
Title:Security update for apache2 (Important)
Description:

This update for apache2 fixes the following issues:

Security issues fixed:

- CVE-2019-9517: Fixed HTTP/2 implementations that are vulnerable to unconstrained interal data buffering (bsc#1145575). - CVE-2019-10081: Fixed mod_http2 that is vulnerable to memory corruption on early pushes (bsc#1145742). - CVE-2019-10082: Fixed mod_http2 that is vulnerable to read-after-free in h2 connection shutdown (bsc#1145741). - CVE-2019-10092: Fixed limited cross-site scripting in mod_proxy (bsc#1145740). - CVE-2019-10097: Fixed mod_remoteip stack buffer overflow and NULL pointer dereference (bsc#1145739). - CVE-2019-10098: Fixed mod_rewrite configuration vulnerablility to open redirect (bsc#1145738).

This update was imported from the SUSE:SLE-15:Update update project.
Family:unixClass:patch
Status:Reference(s):1145575
1145738
1145739
1145740
1145741
1145742
CVE-2019-10081
CVE-2019-10082
CVE-2019-10092
CVE-2019-10097
CVE-2019-10098
CVE-2019-9517
openSUSE-SU-2019:2051-1
Platform(s):openSUSE Leap 15.1
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • apache2-2.4.33-lp151.8.6.1 is installed
  • OR apache2-devel-2.4.33-lp151.8.6.1 is installed
  • OR apache2-doc-2.4.33-lp151.8.6.1 is installed
  • OR apache2-event-2.4.33-lp151.8.6.1 is installed
  • OR apache2-example-pages-2.4.33-lp151.8.6.1 is installed
  • OR apache2-prefork-2.4.33-lp151.8.6.1 is installed
  • OR apache2-utils-2.4.33-lp151.8.6.1 is installed
  • OR apache2-worker-2.4.33-lp151.8.6.1 is installed
  • BACK