{"affected":[{"ecosystem_specific":{"binaries":[{"apache2":"2.4.10-14.28.1","apache2-doc":"2.4.10-14.28.1","apache2-example-pages":"2.4.10-14.28.1","apache2-prefork":"2.4.10-14.28.1","apache2-utils":"2.4.10-14.28.1","apache2-worker":"2.4.10-14.28.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"apache2","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.10-14.28.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for apache2 fixes several issues.\n\nThese security issues were fixed:\n    \n- CVE-2017-9798: Prevent use-after-free use of memory that allowed for an\n  information leak via OPTIONS (bsc#1058058)\n- CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest could have\n  lead to leakage of potentially confidential information, and a segfault in\n  other cases resulting in DoS (bsc#1048576).\n- CVE-2017-7679: mod_mime could have read one byte past the end of a buffer\n  when sending a malicious Content-Type response header (bsc#1045060).\n- CVE-2017-3169: mod_ssl may dereferenced a NULL pointer when third-party\n  modules call ap_hook_process_connection() during an HTTP request to an HTTPS\n  port allowing for DoS (bsc#1045062).\n- CVE-2017-3167: Use of the ap_get_basic_auth_pw() by third-party modules\n  outside of the authentication phase may have lead to authentication\n  requirements being bypassed (bsc#1045065).\n\nThese non-security issues were fixed:\n\n- remove /usr/bin/http2 symlink only during apache2 package \n  uninstall, not upgrade (bsc#1041830)\n- gensslcert: use hostname when fqdn is too long (bsc#1035829)\n- add NotifyAccess=all to service file (bsc#980663)\n","id":"SUSE-SU-2017:2756-1","modified":"2017-10-18T11:46:36Z","published":"2017-10-18T11:46:36Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20172756-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1035829"},{"type":"REPORT","url":"https://bugzilla.suse.com/1041830"},{"type":"REPORT","url":"https://bugzilla.suse.com/1045060"},{"type":"REPORT","url":"https://bugzilla.suse.com/1045062"},{"type":"REPORT","url":"https://bugzilla.suse.com/1045065"},{"type":"REPORT","url":"https://bugzilla.suse.com/1048576"},{"type":"REPORT","url":"https://bugzilla.suse.com/1058058"},{"type":"REPORT","url":"https://bugzilla.suse.com/980663"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3167"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3169"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9788"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9798"}],"related":["CVE-2017-3167","CVE-2017-3169","CVE-2017-7679","CVE-2017-9788","CVE-2017-9798"],"summary":"Security update for apache2","upstream":["CVE-2017-3167","CVE-2017-3169","CVE-2017-7679","CVE-2017-9788","CVE-2017-9798"]}