SuSE 11.3 Security Update : Apache Web Server (SAT Patch Number 9542)

This script is Copyright (C) 2014-2015 Tenable Network Security, Inc.


Synopsis :

The remote SuSE 11 host is missing one or more security updates.

Description :

This update for the Apache Web Server provides the following fixes :

- Fixed a heap-based buffer overflow on apache module
mod_status. (bnc#887765, CVE-2014-0226)

- Properly remove whitespace characters from CDATA
sections to avoid remote denial of service by crashing
the Apache Server process. (bnc#869105, CVE-2013-6438)

- Correction to parsing of cookie content; this can lead
to a crash with a specially designed cookie sent to the
server. (bnc#869106, CVE-2014-0098)

- ECC support should not be missing. (bnc#859916) This
update also introduces a new configuration parameter
CGIDScriptTimeout, which defaults to the value of
parameter Timeout. CGIDScriptTimeout is set to 60s if
mod_cgid is loaded/active, via
/etc/apache2/conf.d/cgid-timeout.conf. The new directive
and its effect prevent request workers to be eaten until
starvation if cgi programs do not send output back to
the server within the timeout set by CGIDScriptTimeout.
(bnc#887768, CVE-2014-0231)

See also :

https://bugzilla.novell.com/show_bug.cgi?id=859916
https://bugzilla.novell.com/show_bug.cgi?id=869105
https://bugzilla.novell.com/show_bug.cgi?id=869106
https://bugzilla.novell.com/show_bug.cgi?id=887765
https://bugzilla.novell.com/show_bug.cgi?id=887768
http://support.novell.com/security/cve/CVE-2013-6438.html
http://support.novell.com/security/cve/CVE-2014-0098.html
http://support.novell.com/security/cve/CVE-2014-0226.html
http://support.novell.com/security/cve/CVE-2014-0231.html

Solution :

Apply SAT patch number 9542.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)

Family: SuSE Local Security Checks

Nessus Plugin ID: 77048 ()

Bugtraq ID:

CVE ID: CVE-2013-6438
CVE-2014-0098
CVE-2014-0226
CVE-2014-0231

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now