SUSE-SU-2017:1997-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1997-1
SUSE-SU-2017:1997-1
Summary: Security update for apache2
Details: This update provides apache2 2.2.34, which brings many fixes and enhancements: Security issues fixed: - CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest. (bsc#1048576) Bug fixes: - Remove /usr/bin/http2 link only during package uninstall, not upgrade. (bsc#1041830) - Don't put the backend in error state (by default) when 500/503 error code is overridden. (bsc#951692) - Allow single-char field names inadvertently disallowed in 2.2.32.
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171997-1/, https://bugzilla.suse.com/1041830, https://bugzilla.suse.com/1048576, https://bugzilla.suse.com/951692, https://www.suse.com/security/cve/CVE-2017-9788
Affected packages
Package
Name: apache2
Purl: pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
