Ubuntu 12.04 LTS : apache2 update (USN-2625-1)

Medium Nessus Plugin ID 83972


The remote Ubuntu host is missing a security-related patch.


As a security improvement, this update makes the following changes to the Apache package in Ubuntu 12.04 LTS :

Added support for ECC keys and ECDH ciphers.

The SSLProtocol configuration directive now allows specifying the TLSv1.1 and TLSv1.2 protocols.

Ephemeral key handling has been improved, including allowing DH parameters to be loaded from the SSL certificate file specified in SSLCertificateFile.

The export cipher suites are now disabled by default.

Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.


Update the affected apache2.2-bin package.

Plugin Details

Severity: Medium

ID: 83972

File Name: ubuntu_USN-2625-1.nasl

Version: $Revision: 2.5 $

Type: local

Agent: unix

Published: 2015/06/03

Modified: 2016/05/24

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:F/RL:TF/RC:ND

Vulnerability Information

CPE: p-cpe:/a:canonical:ubuntu_linux:apache2.2-bin, cpe:/o:canonical:ubuntu_linux:12.04:-:lts

Required KB Items: Host/cpu, Host/Ubuntu, Host/Ubuntu/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2015/06/02

Reference Information

OSVDB: 122331

USN: 2625-1