Oval Definition:oval:org.opensuse.security:def:82205
Revision Date:2018-10-18Version:1
Title:Security update for apache2 (Moderate)
Description:

This update for apache2 fixes the following issues:

Security issues fixed:

- CVE-2016-8743: Fixed liberal whitespace interpretation accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution. (bsc#1016715) - CVE-2016-4975: Fixed possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes which prohibit CR or LF injection into the 'Location' or other outbound header key or value. (bsc#1104826)
Family:unixClass:patch
Status:Reference(s):1016715
1104826
CVE-2016-4975
CVE-2016-8743
SUSE-SU-2018:2815-2
Platform(s):SUSE Linux Enterprise Server 12 SP2-BCL
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • apache2-2.4.23-29.24.1 is installed
  • OR apache2-doc-2.4.23-29.24.1 is installed
  • OR apache2-example-pages-2.4.23-29.24.1 is installed
  • OR apache2-prefork-2.4.23-29.24.1 is installed
  • OR apache2-utils-2.4.23-29.24.1 is installed
  • OR apache2-worker-2.4.23-29.24.1 is installed
  • BACK