Overview

Request 333177 accepted

13.1:
- add httpd-2.4.6-ap_some_auth_required_API_unusable.patch to
replace ap_some_auth_required (unusable in Apache httpd 2.4)
with new ap_some_authn_required and ap_force_authn hook
[bnc#938723], [CVE-2015-3185]
- add httpd-2.4.6-chunk_header_parsing_defect.patch to parse chunk
headers properly [bnc#938728], [CVE-2015-3183]

13.2:
- add httpd-2.4.10-ap_some_auth_required_API_unusable.patch to
replace ap_some_auth_required (unusable in Apache httpd 2.4)
with new ap_some_authn_required and ap_force_authn hook
[bnc#938723], [CVE-2015-3185]
- add httpd-2.4.10-chunk_header_parsing_defect.patch to parse chunk
headers properly [bnc#938728], [CVE-2015-3183]
- fix Logjam vulnerability: change SSLCipherSuite cipherstring to
disable export cipher suites and deploy Ephemeral Elliptic-Curve
Diffie-Hellman (ECDHE) ciphers. Adjust 'gensslcert' script to
generate a strong and unique Diffie Hellman Group and append it
to the server certificate file [bnc#931723], [CVE-2015-4000]

Request History
Kristyna Streitova's avatar

kstreitova created request

13.1:
- add httpd-2.4.6-ap_some_auth_required_API_unusable.patch to
replace ap_some_auth_required (unusable in Apache httpd 2.4)
with new ap_some_authn_required and ap_force_authn hook
[bnc#938723], [CVE-2015-3185]
- add httpd-2.4.6-chunk_header_parsing_defect.patch to parse chunk
headers properly [bnc#938728], [CVE-2015-3183]

13.2:
- add httpd-2.4.10-ap_some_auth_required_API_unusable.patch to
replace ap_some_auth_required (unusable in Apache httpd 2.4)
with new ap_some_authn_required and ap_force_authn hook
[bnc#938723], [CVE-2015-3185]
- add httpd-2.4.10-chunk_header_parsing_defect.patch to parse chunk
headers properly [bnc#938728], [CVE-2015-3183]
- fix Logjam vulnerability: change SSLCipherSuite cipherstring to
disable export cipher suites and deploy Ephemeral Elliptic-Curve
Diffie-Hellman (ECDHE) ciphers. Adjust 'gensslcert' script to
generate a strong and unique Diffie Hellman Group and append it
to the server certificate file [bnc#931723], [CVE-2015-4000]


Maintenance Bot's avatar

maintbot added apache2 as a reviewer

Submission by someone who is not maintainer in the devel project. Please review


Maintenance Bot's avatar

maintbot accepted review

accepted


Petr Gajdos's avatar

pgajdos accepted review

ok


Petr Gajdos's avatar

pgajdos approved review

ok


Marcus Meissner's avatar

msmeissn moved maintenance target to openSUSE:Maintenance:4048


Marcus Meissner's avatar

msmeissn accepted request

ok

openSUSE Build Service is sponsored by