Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Mailing Lists RSS Blog New entry Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)
  - NEW -

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


SUSE update for apache and apache2 Advisory Available in German 

Secunia Advisory: SA29640  
Release Date: 2008-04-07

Critical:
Less critical
Impact: Cross Site Scripting
DoS
Where: From remote
Solution Status: Vendor Patch

OS:openSUSE 10.2
openSUSE 10.3
SUSE Linux 10.1
SUSE Linux Enterprise Server 10
SUSE Linux Enterprise Server 9

Software:Novell Open Enterprise Server 1.x

CVE reference:CVE-2006-3918 (Secunia mirror)
CVE-2007-5000 (Secunia mirror)
CVE-2007-6203 (Secunia mirror)
CVE-2007-6388 (Secunia mirror)
CVE-2007-6421 (Secunia mirror)
CVE-2007-6422 (Secunia mirror)
CVE-2008-0005 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
SUSE has issued an update for apache and apache2. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and malicious users to cause a DoS (Denial of Service).

For more information:
SA21172
SA27906
SA28046

Solution:
Apply updated packages.

x86 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/apache2-2.2.3-24.i586.rpm
f03e4b8274d7152b45efd72e7cde61b5

ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/apache2-devel-2.2.3-24.i586.rpm
ef8e006c4acfea843329bf2fc12b79fd

ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/apache2-doc-2.2.3-24.i586.rpm
51ecfcb9bb6d8c8f08efc97d70b8abbe

ftp://ftp.suse.com/pub/suse/update/10...ache2-example-pages-2.2.3-24.i586.rpm
ce37cfd168b627b540e957da18e5ec8f

ftp://ftp.suse.com/pub/suse/update/10...586/apache2-prefork-2.2.3-24.i586.rpm
0484c1e9d00bd24b5152c562da9ba047

ftp://ftp.suse.com/pub/suse/update/10...i586/apache2-worker-2.2.3-24.i586.rpm
b19e229f483a737b25f2aa53c190f92a

SUSE LINUX 10.1:

ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/apache2-2.2.3-16.17.3.i586.rpm
06c0701d4bd315fb0f644b4fb30d8a95

ftp://ftp.suse.com/pub/suse/update/10.../apache2-devel-2.2.3-16.17.3.i586.rpm
45718ef5161e3544321676e3dd8eca64

ftp://ftp.suse.com/pub/suse/update/10...86/apache2-doc-2.2.3-16.17.3.i586.rpm
65bdf31d9f940c0b96f7732d0eaf9e0b

ftp://ftp.suse.com/pub/suse/update/10...-example-pages-2.2.3-16.17.3.i586.rpm
f8e44ce88c837172d82871bebb06ffd4

ftp://ftp.suse.com/pub/suse/update/10...pache2-prefork-2.2.3-16.17.3.i586.rpm
526d93881e73786ee7f00ef21936ddd0

ftp://ftp.suse.com/pub/suse/update/10...apache2-worker-2.2.3-16.17.3.i586.rpm
1b42cc7478d521000b6566bec22d4109

openSUSE 10.3:

http://download.opensuse.org/pub/open.../rpm/i586/apache2-2.2.4-70.4.i586.rpm
2922d4f0980462aa93cc93f74001f7c8

http://download.opensuse.org/pub/open...586/apache2-devel-2.2.4-70.4.i586.rpm
e80c2f655b566a82ebe3a0d8b95b365e

http://download.opensuse.org/pub/open.../i586/apache2-doc-2.2.4-70.4.i586.rpm
a0f13f91c739c7e8deed206136d710ae

http://download.opensuse.org/pub/open...he2-example-pages-2.2.4-70.4.i586.rpm
5970a02072fa94016f9317641c66bbf5

http://download.opensuse.org/pub/open...6/apache2-prefork-2.2.4-70.4.i586.rpm
5b74451cf3b6d4c82da35b3a20cd6e4a

http://download.opensuse.org/pub/open...586/apache2-utils-2.2.4-70.4.i586.rpm
fecb129d6f984f502f4b96e6e74a1a4e

http://download.opensuse.org/pub/open...86/apache2-worker-2.2.4-70.4.i586.rpm
d5f5ff376fbe11104ee244b5fbbb3e06

Power PC Platform:

openSUSE 10.3:

http://download.opensuse.org/pub/open....3/rpm/ppc/apache2-2.2.4-70.4.ppc.rpm
a2f1e111c2f22510e37c5c6aa31644c7

http://download.opensuse.org/pub/open.../ppc/apache2-devel-2.2.4-70.4.ppc.rpm
992fe3cb04a01a3f20ef149f22ad8dec

http://download.opensuse.org/pub/open...pm/ppc/apache2-doc-2.2.4-70.4.ppc.rpm
4a1c3ecbd61659cae402818e36c6c849

http://download.opensuse.org/pub/open...che2-example-pages-2.2.4-70.4.ppc.rpm
2fd3d31bea6ac3a624816f96418c8abb

http://download.opensuse.org/pub/open...pc/apache2-prefork-2.2.4-70.4.ppc.rpm
a6b81c7bba5e2ee49132c4e9b04849ba

http://download.opensuse.org/pub/open.../ppc/apache2-utils-2.2.4-70.4.ppc.rpm
d23423196ff4f33d6f3aafe42a2edb88

http://download.opensuse.org/pub/open...ppc/apache2-worker-2.2.4-70.4.ppc.rpm
98eae0b512e9758763725ecf48e87154

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/apache2-2.2.3-24.ppc.rpm
01639c47e83d965858231060b99f163a

ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/apache2-devel-2.2.3-24.ppc.rpm
f0c506948d4662ccf850c3ef784aeb10
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/apache2-doc-2.2.3-24.ppc.rpm
7720848272448f257a9d8a5492d59119

ftp://ftp.suse.com/pub/suse/update/10...pache2-example-pages-2.2.3-24.ppc.rpm
bb9a072748358dbd84e9a496a634aa3a

ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/apache2-prefork-2.2.3-24.ppc.rpm
4cab7f565ef9b5ba23c5158b7fa16245

ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/apache2-worker-2.2.3-24.ppc.rpm
71774427d3c37bf7dc3dfbdd475a3499

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/apache2-2.2.3-16.17.3.ppc.rpm
f2a8afbab90fbd03ea8f197a5ce8f65e

ftp://ftp.suse.com/pub/suse/update/10...c/apache2-devel-2.2.3-16.17.3.ppc.rpm
44f8fe684f1eab3f9a6ebb65087de90b

ftp://ftp.suse.com/pub/suse/update/10...ppc/apache2-doc-2.2.3-16.17.3.ppc.rpm
1fe8f99590d355d60ed4cd653b23a6d7

ftp://ftp.suse.com/pub/suse/update/10...2-example-pages-2.2.3-16.17.3.ppc.rpm
2270c3c1dbddf55952d12c00e5e69217

ftp://ftp.suse.com/pub/suse/update/10...apache2-prefork-2.2.3-16.17.3.ppc.rpm
81b0ded89d7109bd790081d7e734b780

ftp://ftp.suse.com/pub/suse/update/10.../apache2-worker-2.2.3-16.17.3.ppc.rpm
d13888fba051f3d508ee8baeca99bf96

x86-64 Platform:

openSUSE 10.2:

ftp://ftp.suse.com/pub/suse/update/10.2/rpm/x86_64/apache2-2.2.3-24.x86_64.rpm
cb086d72cfa22d69ffb77401a3873b27

ftp://ftp.suse.com/pub/suse/update/10..._64/apache2-devel-2.2.3-24.x86_64.rpm
b13ea6a67a114d197e0f97cf83fb1712

ftp://ftp.suse.com/pub/suse/update/10...86_64/apache2-doc-2.2.3-24.x86_64.rpm
6721aef0cdabf944ffdc7917bafa22db

ftp://ftp.suse.com/pub/suse/update/10...he2-example-pages-2.2.3-24.x86_64.rpm
475b95ef58b8078af54e6e0051d340c4

ftp://ftp.suse.com/pub/suse/update/10...4/apache2-prefork-2.2.3-24.x86_64.rpm
66683396a06e14ab0a6fafd3af1c1cd3

ftp://ftp.suse.com/pub/suse/update/10...64/apache2-worker-2.2.3-24.x86_64.rpm
260c25e62faf98def97d7f227d931545

SUSE LINUX 10.1:

ftp://ftp.suse.com/pub/suse/update/10...6_64/apache2-2.2.3-16.17.3.x86_64.rpm
391a67b5fbcd657e2ecfba1a459057b2

ftp://ftp.suse.com/pub/suse/update/10...pache2-devel-2.2.3-16.17.3.x86_64.rpm
e78d919d97960714f0bdff45cf984b70

ftp://ftp.suse.com/pub/suse/update/10.../apache2-doc-2.2.3-16.17.3.x86_64.rpm
52ee6e668465921cedb8ec6db723180b

ftp://ftp.suse.com/pub/suse/update/10...xample-pages-2.2.3-16.17.3.x86_64.rpm
8400d2e78b1c2edc522c65a1b099f396

ftp://ftp.suse.com/pub/suse/update/10...che2-prefork-2.2.3-16.17.3.x86_64.rpm
17eef4da8eb3dd2eccace560d7a14e0e

ftp://ftp.suse.com/pub/suse/update/10...ache2-worker-2.2.3-16.17.3.x86_64.rpm
da7b31c3508caf37b650e9cf47359098

openSUSE 10.3:

http://download.opensuse.org/pub/open.../x86_64/apache2-2.2.4-70.4.x86_64.rpm
9ff3ba6a589b6e79f603828937c5c126

http://download.opensuse.org/pub/open...4/apache2-devel-2.2.4-70.4.x86_64.rpm
56b23bc76fbfb0bc0d98b11c63daaf36

http://download.opensuse.org/pub/open..._64/apache2-doc-2.2.4-70.4.x86_64.rpm
55ce8aaf6bc7c097999a93efe99da704

http://download.opensuse.org/pub/open...2-example-pages-2.2.4-70.4.x86_64.rpm
1c2d0b400948e83773ba08127ba7fa82

http://download.opensuse.org/pub/open...apache2-prefork-2.2.4-70.4.x86_64.rpm
537ef6542894bf7ad0bdc72ea9e73be7

http://download.opensuse.org/pub/open...4/apache2-utils-2.2.4-70.4.x86_64.rpm
a9d11f6df973e9e71889acfd36ec49c3

http://download.opensuse.org/pub/open.../apache2-worker-2.2.4-70.4.x86_64.rpm
a51618285183cd0b97075be8436ea697

Sources:

openSUSE 10.3:

http://download.opensuse.org/pub/open....3/rpm/src/apache2-2.2.4-70.4.src.rpm
9ac4cf97f58360c61b17b177a72df991

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/apache2-2.2.3-24.src.rpm
10a8ee22535b31519d2ba876c31d5271

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/src/apache2-2.2.3-16.17.3.src.rpm
66e2fed2bd179c17fed7b931900ef0dc

Open Enterprise Server

http://support.novell.com/techcenter/psdb/484f33da03a9e3e4632f40254c4a96a3.html

http://support.novell.com/techcenter/psdb/2c87b234552522821a81df2a63d03f8c.html

Novell Linux POS 9

http://support.novell.com/techcenter/psdb/484f33da03a9e3e4632f40254c4a96a3.html

http://support.novell.com/techcenter/psdb/2c87b234552522821a81df2a63d03f8c.html

Novell Linux Desktop 9

http://support.novell.com/techcenter/psdb/2c87b234552522821a81df2a63d03f8c.html

Novell Linux Desktop 9 SDK

http://support.novell.com/techcenter/psdb/484f33da03a9e3e4632f40254c4a96a3.html

http://support.novell.com/techcenter/psdb/2c87b234552522821a81df2a63d03f8c.html

SUSE SLES 9

http://support.novell.com/techcenter/psdb/484f33da03a9e3e4632f40254c4a96a3.html

http://support.novell.com/techcenter/psdb/2c87b234552522821a81df2a63d03f8c.html

SUSE Linux Enterprise Server 10 SP1

http://support.novell.com/techcenter/psdb/652745fced1c4af0216a2f3d8430a472.html

SLE SDK 10 SP1

http://support.novell.com/techcenter/psdb/652745fced1c4af0216a2f3d8430a472.html

Original Advisory:
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html

Other References:
SA21172:
http://secunia.com/advisories/21172/

SA27906:
http://secunia.com/advisories/27906/

SA28046:
http://secunia.com/advisories/28046/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

325 Related Secunia Security Advisories, displaying 10

1. SUSE Update for Multiple Packages
2. SUSE Update for Multiple Packages
3. SUSE update for OpenOffice_org
4. SUSE update for IBM Java
5. SUSE update for clamav
6. SUSE update for flash-player
7. SUSE update for openssh and opera
8. SUSE update for cups
9. SUSE update for MozillaFirefox
10. SUSE Updates for Multiple Packages

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
Debian OpenSSL Predictable Random Number Generator and Update
2.
Microsoft Word Two Code Execution Vulnerabilities
3.
Microsoft Malware Protection Engine File Parsing Denial of Service
4.
Ubuntu update for openssl
5.
Microsoft Publisher Object Handler Validation Vulnerability
6.
Microsoft Windows XP I2O Utility Filter Driver Privilege Escalation
7.
Novell Client Login Long Username/Contex t Buffer Overflow
8.
Citrix Access Gateway Unspecified Authentication Bypass
9.
Build A Niche Store "q" Cross-Site Scripting
10.
Gentoo update for aterm, eterm, rxvt, mrxvt, multi-aterm, wterm, and rxvt-unicode





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia