First published: Tue Jun 02 2015(Updated: )
As a security improvement, this update makes the following changes to the Apache package in Ubuntu 12.04 LTS: Added support for ECC keys and ECDH ciphers. The SSLProtocol configuration directive now allows specifying the TLSv1.1 and TLSv1.2 protocols. Ephemeral key handling has been improved, including allowing DH parameters to be loaded from the SSL certificate file specified in SSLCertificateFile. The export cipher suites are now disabled by default.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/apache2.2-bin | <2.2.22-1ubuntu1.9 | 2.2.22-1ubuntu1.9 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this update is USN-2625-1.
The title of this update is 'USN-2625-1: Apache HTTP Server update'.
This update adds support for ECC keys and ECDH ciphers, allows specifying the TLSv1.1 and TLSv1.2 protocols in the SSLProtocol configuration directive, and improves ephemeral key handling.
The recommended version of the Apache package to fix this vulnerability is 2.2.22-1ubuntu1.9.
You can find more information about this vulnerability at the following references: [Link 1](https://launchpad.net/bugs/1197884), [Link 2](https://launchpad.net/bugs/1400473), [Link 3](https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.9).