SuSE 10 Security Update : Apache2 (ZYPP Patch Number 7882)

medium Nessus Plugin ID 57298


The remote SuSE 10 host is missing a security-related patch.


This update fixes several security issues in the Apache2 webserver.

- This update also includes several fixes for a mod_proxy reverse exposure via RewriteRule or ProxyPassMatch directives. (CVE-2011-3639 / CVE-2011-3368 / CVE-2011-4317)

- Fixed the SSL renegotiation DoS by disabling renegotiation by default. (CVE-2011-1473)

- Integer overflow in ap_pregsub function resulting in a heap-based buffer overflow could potentially allow local attackers to gain privileges. (CVE-2011-3607)


Apply ZYPP patch number 7882.

See Also

Plugin Details

Severity: Medium

ID: 57298

File Name: suse_apache2-7882.nasl

Version: 1.15

Type: local

Agent: unix

Published: 12/14/2011

Updated: 1/19/2021

Supported Sensors: Nessus Agent

Risk Information


Risk Factor: Medium

Score: 6.3


Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/7/2011

Exploitable With

ExploitHub (EH-14-410)

Reference Information

CVE: CVE-2011-1473, CVE-2011-3368, CVE-2011-3607, CVE-2011-3639, CVE-2011-4317