Oval Definition:oval:org.opensuse.security:def:81349
Revision Date:2017-03-22Version:1
Title:Security update for apache2 (Moderate)
Description:



This update for apache2 fixes the following security issues:

Security issues fixed: - CVE-2016-0736: Protect mod_session_crypto data with a MAC to prevent padding oracle attacks (bsc#1016712). - CVE-2016-2161: Malicious input to mod_auth_digest could have caused the server to crash, resulting in DoS (bsc#1016714). - CVE-2016-8743: Added new directive 'HttpProtocolOptions Strict' to avoid proxy chain misinterpretation (bsc#1016715).

Bugfixes: - Add missing copy of hcuri and hcexpr from the worker to the health check worker (bsc#1019380).
Family:unixClass:patch
Status:Reference(s):1016712
1016714
1016715
1019380
CVE-2016-0736
CVE-2016-2161
CVE-2016-8743
SUSE-SU-2017:0797-1
Platform(s):SUSE Linux Enterprise Server 12 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • apache2-2.4.23-21.1 is installed
  • OR apache2-doc-2.4.23-21.1 is installed
  • OR apache2-example-pages-2.4.23-21.1 is installed
  • OR apache2-prefork-2.4.23-21.1 is installed
  • OR apache2-utils-2.4.23-21.1 is installed
  • OR apache2-worker-2.4.23-21.1 is installed
  • BACK