=========================================================================Ubuntu Security Notice USN-2686-1
July 27, 2015

apache2 vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the Apache HTTP server.

Software Description:
- apache2: Apache HTTP server

Details:

It was discovered that the Apache HTTP Server incorrectly parsed chunk
headers. A remote attacker could possibly use this issue to perform HTTP
request smuggling attacks. (CVE-2015-3183)

It was discovered that the Apache HTTP Server incorrectly handled the
ap_some_auth_required API. A remote attacker could possibly use this issue
to bypass intended access restrictions. This issue only affected Ubuntu
14.04 LTS and Ubuntu 15.04. (CVE-2015-3185)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  apache2.2-bin                   2.4.10-9ubuntu1.1

Ubuntu 14.04 LTS:
  apache2.2-bin                   2.4.7-1ubuntu4.5

Ubuntu 12.04 LTS:
  apache2.2-bin                   2.2.22-1ubuntu1.10

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2686-1
  CVE-2015-3183, CVE-2015-3185

Package Information:
  https://launchpad.net/ubuntu/+source/apache2/2.4.10-9ubuntu1.1
  https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.5
  https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.10


Ubuntu 2686-1: Apache HTTP Server vulnerabilities

July 27, 2015
Several security issues were fixed in the Apache HTTP server.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: apache2.2-bin 2.4.10-9ubuntu1.1 Ubuntu 14.04 LTS: apache2.2-bin 2.4.7-1ubuntu4.5 Ubuntu 12.04 LTS: apache2.2-bin 2.2.22-1ubuntu1.10 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2686-1

CVE-2015-3183, CVE-2015-3185

Severity
July 27, 2015

Package Information

https://launchpad.net/ubuntu/+source/apache2/2.4.10-9ubuntu1.1 https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.5 https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.10

Related News