SUSE-SA:2005:046: apache,apache2

high Nessus Plugin ID 19925

Synopsis

The remote host is missing a vendor-supplied security patch

Description

The remote host is missing the patch for the advisory SUSE-SA:2005:046 (apache,apache2).


A security flaw was found in the Apache and Apache2 web servers which allows remote attacker to 'smuggle' requests past filters by providing handcrafted header entries.

Fixed Apache 2 server packages were released on July 26th, fixed Apache 1 server packages were released on August 15th.

This issue is tracked by the Mitre CVE ID CVE-2005-2088.

The Apache2 packages additionally fix a single byte overflow in the SSL CRL handling functionality, tracked by the Mitre CVE ID CVE-2005-1268.

The Apache1 packages additionally fix a harmless local buffer overflow in htpasswd.

Solution

http://www.suse.de/security/advisories/2005_46_apache.html

Plugin Details

Severity: High

ID: 19925

File Name: suse_SA_2005_046.nasl

Version: 1.9

Agent: unix

Published: 10/5/2005

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Vulnerability Information

Required KB Items: Host/SuSE/rpm-list