Synopsis
The remote host is missing a vendor-supplied security patch
Description
The remote host is missing the patch for the advisory SUSE-SA:2005:046 (apache,apache2).
A security flaw was found in the Apache and Apache2 web servers which allows remote attacker to 'smuggle' requests past filters by providing handcrafted header entries.
Fixed Apache 2 server packages were released on July 26th, fixed Apache 1 server packages were released on August 15th.
This issue is tracked by the Mitre CVE ID CVE-2005-2088.
The Apache2 packages additionally fix a single byte overflow in the SSL CRL handling functionality, tracked by the Mitre CVE ID CVE-2005-1268.
The Apache1 packages additionally fix a harmless local buffer overflow in htpasswd.
Solution
http://www.suse.de/security/advisories/2005_46_apache.html
Plugin Details
File Name: suse_SA_2005_046.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Vulnerability Information
Required KB Items: Host/SuSE/rpm-list