Security update for apache2
This update for apache2 fixes the following issues: - CVE-2025-55753: Fixed mod_md (ACME) unintended retry intervals (bsc#1254511) - CVE-2025-65082: Fixed CGI environment variable override (bsc#1254514) - CVE-2025-58098: Fixed Server Side Includes adding query string to #exec cmd=... (bsc#1254512) - CVE-2025-66200: Fixed mod_userdir+suexec bypass via AllowOverride FileInfo (bsc#1254515)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for apache2 fixes the following issues: - CVE-2025-55753: Fixed mod_md (ACME) unintended retry intervals (bsc#1254511) - CVE-2025-65082: Fixed CGI environment variable override (bsc#1254514) - CVE-2025-58098: Fixed Server Side Includes adding query string to #exec cmd=... (bsc#1254512) - CVE-2025-66200: Fixed mod_userdir+suexec bypass via AllowOverride FileInfo (bsc#1254515)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1254511
- https://bugzilla.suse.com/1254512
- https://bugzilla.suse.com/1254514
- https://bugzilla.suse.com/1254515
- https://www.suse.com/security/cve/CVE-2025-55753
- https://www.suse.com/security/cve/CVE-2025-58098
- https://www.suse.com/security/cve/CVE-2025-65082
- https://www.suse.com/security/cve/CVE-2025-66200
- https://www.suse.com/support/update/announcement/2025/suse-su-20254488-1/