<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="0683ec2df667efa4b179f003d0da49d3"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="1419">
  <id>dbg111-apache2</id>
  <title>apache2: Security fixes for various vulnerabilities</title>
  <release>openSUSE 11.1</release>
  <issued date="1256082344"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=512583" id="512583" title="bug number 512583" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=513080" id="513080" title="bug number 513080" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=521906" id="521906" title="bug number 521906" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=519194" id="519194" title="bug number 519194" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=539571" id="539571" title="bug number 539571" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=538322" id="538322" title="bug number 538322" type="bugzilla"/>
  </references>
  <description>This update of the Apache webserver fixes various security
issues:
- the option IncludesNOEXEC could be bypassed via .htaccess
  (CVE-2009-1195) 
- mod_proxy could run into an infinite loop when used as
  reverse  proxy (CVE-2009-1890) 
- mod_deflate continued to compress large files even after
  a network connection was closed, causing mod_deflate to
  consume large amounts of CPU (CVE-2009-1891)
- The ap_proxy_ftp_handler function in
  modules/proxy/proxy_ftp.c in the mod_proxy_ftp module
  allows remote FTP servers to cause a denial of service
  (NULL pointer dereference and child process crash) via a
  malformed reply to an EPSV command. (CVE-2009-3094)
- access restriction bypass in mod_proxy_ftp module
  (CVE-2009-3095)
</description>
  <pkglist>
    <collection>
        <package name="apache2-debuginfo" arch="i586" version="2.2.10" release="2.8.1">
          <filename>apache2-debuginfo-2.2.10-2.8.1.i586.rpm</filename>
        </package>
        <package name="apache2-debuginfo" arch="ppc" version="2.2.10" release="2.8.1">
          <filename>apache2-debuginfo-2.2.10-2.8.1.ppc.rpm</filename>
        </package>
        <package name="apache2-debuginfo" arch="x86_64" version="2.2.10" release="2.8.1">
          <filename>apache2-debuginfo-2.2.10-2.8.1.x86_64.rpm</filename>
        </package>
        <package name="apache2-debugsource" arch="i586" version="2.2.10" release="2.8.1">
          <filename>apache2-debugsource-2.2.10-2.8.1.i586.rpm</filename>
        </package>
        <package name="apache2-debugsource" arch="ppc" version="2.2.10" release="2.8.1">
          <filename>apache2-debugsource-2.2.10-2.8.1.ppc.rpm</filename>
        </package>
        <package name="apache2-debugsource" arch="x86_64" version="2.2.10" release="2.8.1">
          <filename>apache2-debugsource-2.2.10-2.8.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
