Ubuntu 12.04 LTS : apache2 update (USN-2625-1)

high Nessus Plugin ID 83972

Synopsis

The remote Ubuntu host is missing a security-related patch.

Description

As a security improvement, this update makes the following changes to the Apache package in Ubuntu 12.04 LTS :

Added support for ECC keys and ECDH ciphers.

The SSLProtocol configuration directive now allows specifying the TLSv1.1 and TLSv1.2 protocols.

Ephemeral key handling has been improved, including allowing DH parameters to be loaded from the SSL certificate file specified in SSLCertificateFile.

The export cipher suites are now disabled by default.

Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected apache2.2-bin package.

See Also

https://usn.ubuntu.com/2625-1/

Plugin Details

Severity: High

ID: 83972

File Name: ubuntu_USN-2625-1.nasl

Version: 2.11

Type: local

Agent: unix

Published: 6/3/2015

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:canonical:ubuntu_linux:apache2.2-bin, cpe:/o:canonical:ubuntu_linux:12.04:-:lts

Required KB Items: Host/cpu, Host/Debian/dpkg-l, Host/Ubuntu, Host/Ubuntu/release

Patch Publication Date: 6/2/2015

Vulnerability Publication Date: 6/2/2015

Reference Information

USN: 2625-1