SUSE-SU-2017:1714-1 -- SLES apache2ID: oval:org.secpod.oval:def:89044879 | Date: (C)2021-07-20 (M)2024-02-19 |
Class: PATCH | Family: unix |
This update for apache2 provides the following fixes: Security issues fixed: - CVE-2017-3167: In Apache use of httpd ap_get_basic_auth_pw outside of the authentication phase could lead to authentication requirements bypass - CVE-2017-3169: In mod_ssl may have a dereference NULL pointer issue which could lead to denial of service - CVE-2017-7679: In mod_mime can buffer over-read by 1 byte, potentially leading to a crash or information disclosure Non-Security issues fixed: - Remove /usr/bin/http2 symlink only during apache2 package uninstall, not upgrade. - In gensslcert, use hostname when fqdn is too long
Platform: |
SUSE Linux Enterprise Server 12 SP2 |