Bug 899836 - (CVE-2014-3581) VUL-1: CVE-2014-3581: apache2: [NULL ptr DoS in mod_cache]
(CVE-2014-3581)
VUL-1: CVE-2014-3581: apache2: [NULL ptr DoS in mod_cache]
Status: RESOLVED FIXED
: 914956 (view as bug list)
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/108842/
maint:released:sle11-sp1:61302 maint:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-10-06 08:13 UTC by Sebastian Krahmer
Modified: 2016-02-17 21:16 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
proposed SLE patches (15.50 KB, application/x-tar)
2014-11-07 17:18 UTC, Kristyna Streitova
Details

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Sebastian Krahmer 2014-10-06 08:16:29 UTC
I think this is a minor issue (NULL ptr deref) so its
enough to fix for Factory and put it on the planned update list.
Comment 2 Sebastian Krahmer 2014-10-06 08:23:35 UTC
Do you happen to know which of the SLE products are affected at all?
Comment 3 Swamp Workflow Management 2014-10-06 22:00:22 UTC
bugbot adjusting priority
Comment 4 Kristyna Streitova 2014-10-27 16:21:45 UTC
The potentially problematic row is 

apr_table_setn(r->headers_out, "Content-Type", ap_make_content_type(r, r->content_type));

Especially if "ap_make_content_type(r, r->content_type)" is not checked for the NULL value. I have searched it through the all maintained versions and there is a list of the files with the occurrence of the problematic row:


SLE 10 SP 3 (httpd-2.2.3)
  - modules/http/byterange_filter.c - fixed
  - modules/http/http_filters.c - affected
  - modules/cache/mod_disk_cache.c - affected
  - modules/cache/mod_mem_cache.c - affected
    
SLE 10 SP 4 (httpd-2.2.3)
  - modules/http/byterange_filter.c - fixed
  - modules/http/http_filters.c - affected
  - modules/cache/mod_disk_cache.c - affected
  - modules/cache/mod_mem_cache.c - affected

SLE 11 SP1 (httpd-2.2.12)
  - modules/http/byterange_filter.c - fixed
  - modules/http/http_filters.c - fixed
  - modules/cache/mod_disk_cache.c - affected
  - modules/cache/mod_mem_cache.c - affected

SLE 12 (httpd-2.4.10)
  - modules/http/byterange_filter.c - fixed
  - modules/http/http_filters.c - fixed
  - modules/cache/cache_util.c - affected


It means SLE 10 SP3, SLE 10 SP4 and SLE 11 SP1 need more than the simple fix above.

For SLE 12 the fix above will be enough.
Comment 5 Kristyna Streitova 2014-11-07 17:18:40 UTC
Created attachment 612825 [details]
proposed SLE patches

I'm attaching the proposed SLE patches. The fix for Factory has already been submitted.
Comment 6 Kristyna Streitova 2014-12-05 17:26:58 UTC
As the patches for SLE are prepared and patch for Factory was submitted, I'm closing this bug.
Comment 7 Marcus Meissner 2015-01-27 11:36:42 UTC
please leave it open until submission... we otherwise might lose track.
Comment 8 Leonardo Chiquitto 2015-02-09 14:19:54 UTC
*** Bug 914956 has been marked as a duplicate of this bug. ***
Comment 9 Swamp Workflow Management 2015-03-11 13:58:54 UTC
An update workflow for this issue was started.
This issue was rated as low.
Please submit fixed packages until 2015-04-08.
https://swamp.suse.de/webswamp/wf/61064
Comment 12 Kristyna Streitova 2015-04-02 16:36:35 UTC
Submitted to:
  - SLE10SP3: https://build.suse.de/request/show/54652
  - SLE11SP1: https://build.suse.de/request/show/53778
  - SLE12: https://build.suse.de/request/show/54654

I'm reassigning it back to security-team.
Comment 13 Swamp Workflow Management 2015-04-08 23:05:28 UTC
SUSE-SU-2015:0689-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 713970,871310,899836,904427,907339,907477
CVE References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    apache2-2.2.12-1.51.52.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    apache2-2.2.12-1.51.52.1
SUSE Linux Enterprise Server 11 SP3 (src):    apache2-2.2.12-1.51.52.1
Comment 14 Swamp Workflow Management 2015-06-01 07:06:06 UTC
SUSE-SU-2015:0974-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 792309,871310,899836,909715,918352,923090
CVE References: CVE-2013-5704,CVE-2014-3581,CVE-2014-8109,CVE-2015-0228
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    apache2-2.4.10-12.1
SUSE Linux Enterprise Server 12 (src):    apache2-2.4.10-12.1
Comment 15 Victor Pereira 2015-06-03 20:11:43 UTC
updates released
Comment 16 Swamp Workflow Management 2015-07-24 12:09:20 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2015-08-07.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/62232