SUSE Container Update Advisory: bci/php-apache ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:2332-1 Container Tags : bci/php-apache:8 , bci/php-apache:8-19.11 , bci/php-apache:latest Container Release : 19.11 Severity : important Type : security References : 1221401 1222330 1222332 CVE-2023-38709 CVE-2024-24795 CVE-2024-27316 ----------------------------------------------------------------- The container bci/php-apache was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:1868-1 Released: Thu May 30 14:23:07 2024 Summary: Security update for apache2 Type: security Severity: important References: 1221401,1222330,1222332,CVE-2023-38709,CVE-2024-24795,CVE-2024-27316 This update for apache2 fixes the following issues: - CVE-2023-38709: Fixed faulty input validation inside the HTTP response splitting code (bsc#1222330). - CVE-2024-24795: Fixed handling of malicious HTTP splitting response headers in multiple modules (bsc#1222332). - CVE-2024-27316: Fixed HTTP/2 CONTINUATION frames that could have been utilized for DoS attacks (bsc#1221401). The following package changes have been done: - apache2-utils-2.4.51-150400.6.17.1 updated - apache2-2.4.51-150400.6.17.1 updated - apache2-prefork-2.4.51-150400.6.17.1 updated