Bug 938723 (CVE-2015-3185) - VUL-1: CVE-2015-3185: apache2: replacement of ap_some_auth_required with new ap_some_authn_required and ap_force_authn
Summary: VUL-1: CVE-2015-3185: apache2: replacement of ap_some_auth_required with new ...
Status: RESOLVED FIXED
: 939516 (view as bug list)
Alias: CVE-2015-3185
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Deadline: 2015-08-07
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/119035/
Whiteboard: maint:running:62232:moderate CVSSv2:...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-07-20 11:13 UTC by Johannes Segitz
Modified: 2017-09-13 15:46 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
2.4.x fix for CVE-2015-3185 (7.17 KB, patch)
2015-08-05 16:11 UTC, Kristyna Streitova
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2015-07-20 11:13:04 UTC
rh#1243888

http://www.apache.org/dist/httpd/CHANGES_2.4.16
     Replacement of ap_some_auth_required (unusable in Apache httpd 2.4)
     with new ap_some_authn_required and ap_force_authn hook.  [Ben Reser]

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1243888
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3185
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-3185.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3185
Comment 2 Swamp Workflow Management 2015-07-20 22:00:26 UTC
bugbot adjusting priority
Comment 3 Swamp Workflow Management 2015-07-24 12:07:44 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2015-08-07.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/62232
Comment 5 Kristyna Streitova 2015-08-05 15:49:08 UTC
Fixes:
=====

- 2.4.x fix svn: http://svn.apache.org/viewvc?view=revision&revision=1684525
- 2.4.x fix git: https://github.com/apache/httpd/commit/c3f98ce69b9c8ddc936380e9d7cf03feca809558 (they have a wrong CVE there but it's the same patch as in svn)


Affected products (only 2.4.x branch is affected by this issue):
=================

|    Product    | Version |
|---------------|---------|
| SLE12         | 2.4.10  |
| openSUSE 13.1 | 2.4.6   |
| openSUSE 13.2 | 2.4.10  |
Comment 6 Kristyna Streitova 2015-08-05 16:11:24 UTC
Created attachment 642959 [details]
2.4.x fix for CVE-2015-3185

A patch for apache 2.4.x
Comment 7 Kristyna Streitova 2015-08-06 15:34:36 UTC
*** Bug 939516 has been marked as a duplicate of this bug. ***
Comment 8 Kristyna Streitova 2015-08-07 14:53:41 UTC
SLE12 fix submitted. See mr#64852 (https://build.suse.de/request/show/64852)
Comment 9 Petr Gajdos 2015-08-07 15:17:31 UTC
Kristyna, great, thanks.

Should I do the rest or will you do?
Comment 10 Kristyna Streitova 2015-08-07 15:20:14 UTC
(In reply to Petr Gajdos from comment #9)
> Kristyna, great, thanks.
> 
> Should I do the rest or will you do?

I will do it next week.
Comment 11 Kristyna Streitova 2015-09-23 13:56:40 UTC
Submitted to openSUSE 13.1 & 13.2: https://build.opensuse.org/request/show/333177

Closing.
Comment 12 Bernhard Wiedemann 2015-09-23 14:00:14 UTC
This is an autogenerated message for OBS integration:
This bug (938723) was mentioned in
https://build.opensuse.org/request/show/333177 13.2+13.1 / apache2
Comment 13 Kristyna Streitova 2015-09-23 14:01:27 UTC
Sorry, there still is a running update. Rather reopening and reassigning to security-team.
Comment 14 Swamp Workflow Management 2015-10-06 07:09:53 UTC
openSUSE-SU-2015:1684-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 931723,938723,938728
CVE References: CVE-2015-3183,CVE-2015-3185,CVE-2015-4000
Sources used:
openSUSE 13.2 (src):    apache2-2.4.10-28.1
openSUSE 13.1 (src):    apache2-2.4.6-6.50.1
Comment 16 Swamp Workflow Management 2015-10-30 16:12:24 UTC
SUSE-SU-2015:1851-1: An update that solves four vulnerabilities and has 9 fixes is now available.

Category: security (moderate)
Bug References: 444878,869790,911159,915666,927845,930228,931002,931723,938723,938728,939516,949766,949771
CVE References: CVE-2014-8111,CVE-2015-3183,CVE-2015-3185,CVE-2015-4000
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    apache2-2.4.10-14.10.1
SUSE Linux Enterprise Server 12 (src):    apache2-2.4.10-14.10.1, apache2-mod_auth_kerb-5.4-2.4.1, apache2-mod_jk-1.2.40-2.6.1, apache2-mod_security2-2.8.0-3.4.1
SUSE Enterprise Storage 1.0 (src):    apache2-mod_fastcgi-2.4.7-3.4.1
Comment 17 Marcus Meissner 2016-01-22 08:10:45 UTC
done