USN-2625-1: Apache HTTP Server update

Ubuntu Security Notice USN-2625-1

2nd June, 2015

apache2 update

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 12.04 LTS

Summary

Several security improvements have been made to the Apache HTTP Server.

Software description

  • apache2
    – Apache HTTP server

Details

As a security improvement, this update makes the following changes to
the Apache package in Ubuntu 12.04 LTS:

Added support for ECC keys and ECDH ciphers.

The SSLProtocol configuration directive now allows specifying the TLSv1.1
and TLSv1.2 protocols.

Ephemeral key handling has been improved, including allowing DH parameters
to be loaded from the SSL certificate file specified in SSLCertificateFile.

The export cipher suites are now disabled by default.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 12.04 LTS:
apache2.2-bin

2.2.22-1ubuntu1.9

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

This update may cause DH parameters to change which could impact certain Java
clients. See http://httpd.apache.org/docs/2.2/ssl/ssl_faq.html#javadh for more
information.

References

LP: 1197884,

LP: 1400473

Leave a Reply