Recommended update for apache2
This update for the Apache Web Server introduces directives to control two protocol options: * HttpContentLengthHeadZero: Allow responses to HEAD request with Content-Length of 0 * HttpExpectStrict: Allow the administrator to control whether clients must send '100-continue' MODULE_MAGIC_NUMBER_MINOR has been increased to 24, as this change is not forward-compatible. Modules built against this release might not work correctly with older releases of the Apache Web Server.
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the Apache Web Server introduces directives to control two protocol options: * HttpContentLengthHeadZero: Allow responses to HEAD request with Content-Length of 0 * HttpExpectStrict: Allow the administrator to control whether clients must send '100-continue' MODULE_MAGIC_NUMBER_MINOR has been increased to 24, as this change is not forward-compatible. Modules built against this release might not work correctly with older releases of the Apache Web Server.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/713970
- https://bugzilla.suse.com/791794
- https://bugzilla.suse.com/815621
- https://bugzilla.suse.com/829056
- https://bugzilla.suse.com/829057
- https://bugzilla.suse.com/844212
- https://bugzilla.suse.com/852401
- https://bugzilla.suse.com/859916
- https://bugzilla.suse.com/869105
- https://bugzilla.suse.com/869106
- https://bugzilla.suse.com/871310
- https://bugzilla.suse.com/887765
- https://bugzilla.suse.com/887768
- https://bugzilla.suse.com/894225
- https://bugzilla.suse.com/899836
- https://bugzilla.suse.com/904427
- https://bugzilla.suse.com/907339
- https://bugzilla.suse.com/907477
- https://www.suse.com/security/cve/CVE-2003-1418
- https://www.suse.com/security/cve/CVE-2013-1862
- https://www.suse.com/security/cve/CVE-2013-1896
- https://www.suse.com/security/cve/CVE-2013-5704
- https://www.suse.com/security/cve/CVE-2013-6438
- https://www.suse.com/security/cve/CVE-2014-0098
- https://www.suse.com/security/cve/CVE-2014-0226
- https://www.suse.com/security/cve/CVE-2014-0231
- https://www.suse.com/security/cve/CVE-2014-3581
- https://www.suse.com/support/update/announcement/2015/suse-su-20150689-1/