Revision Date: | 2020-12-01 | Version: | 1 |
Title: | Security update for apache2 (Moderate) |
Description: |
This update for apache2 fixes the following issues:
- CVE-2020-9490: Fixed a crash caused by a specially crafted value for the 'Cache-Digest' header in a HTTP/2 request (bsc#1175071). - CVE-2020-11984: Fixed an information disclosure bug in mod_proxy_uwsgi (bsc#1175074). - CVE-2020-11993: When trace/debug was enabled for the HTTP/2 module logging statements were made on the wrong connection (bsc#1175070).
- Solve a crash in mod_proxy_uwsgi for empty values of environment variables. (bsc#1174052)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1125433 1136981 1136986 1136992 1137930 1174052 1175070 1175071 1175074 CVE-2019-12447 CVE-2019-12448 CVE-2019-12449 CVE-2019-12795 CVE-2020-11984 CVE-2020-11993 CVE-2020-9490 openSUSE-SU-2019:1697-1 SUSE-SU-2020:2311-1
|
Platform(s): | openSUSE Leap 15.1 SUSE Linux Enterprise Module for Server Applications 15 SP2
| Product(s): | |
Definition Synopsis |
openSUSE Leap 15.1 is installed AND Package Information
gvfs-1.34.2.1-lp151.6.3 is installed
OR gvfs-32bit-1.34.2.1-lp151.6.3 is installed
OR gvfs-backend-afc-1.34.2.1-lp151.6.3 is installed
OR gvfs-backend-samba-1.34.2.1-lp151.6.3 is installed
OR gvfs-backends-1.34.2.1-lp151.6.3 is installed
OR gvfs-devel-1.34.2.1-lp151.6.3 is installed
OR gvfs-fuse-1.34.2.1-lp151.6.3 is installed
OR gvfs-lang-1.34.2.1-lp151.6.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
AND Package Information
apache2-2.4.43-3.5 is installed
OR apache2-devel-2.4.43-3.5 is installed
OR apache2-doc-2.4.43-3.5 is installed
OR apache2-worker-2.4.43-3.5 is installed
|