# SLES SP3 and Apache CRIME exploit

**URL:** <https://forums.suse.com/t/sles-sp3-and-apache-crime-exploit/25350>\
**Category:** SLES Updates\
**Created:** [April 8, 2014, 7:12pm UTC](https://forums.suse.com/t/sles-sp3-and-apache-crime-exploit/25350 "2014-04-08T19:12:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dennisdcs](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@dennisdcs](https://forums.suse.com/u/dennisdcs)\
**Post date:** [April 8, 2014, 7:12pm UTC](https://forums.suse.com/t/sles-sp3-and-apache-crime-exploit/25350/1 "2014-04-08T19:12:46Z")

</div>

Is there any fix for it? SLES is using and old version of Apache (2.2.12) and I really don’t want to start having to compile things to get a fixed version.

---

<div class="post-metadata">

**Author:** ![Jens-U](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@Jens-U](https://forums.suse.com/u/Jens-U)\
**Post date:** [April 8, 2014, 7:42pm UTC](https://forums.suse.com/t/sles-sp3-and-apache-crime-exploit/25350/2 "2014-04-08T19:42:00Z")

</div>

Hi dennisdcs,

> [@dennisdcs;20331](#):
>
> Is there any fix for it? SLES is using and old version of Apache (2.2.12) and I really don’t want to start having to compile things to get a fixed version.

generally speaking, SLES is very often using old versions that are patched individually to cover bugs. This is a stability measure - you still get the old behaviour, minus the bugs. But as the version numbers aren’t updated (so not to confuse people to think that the code is based on a newer available version), it is not obvious which patches are included.

See i.e. [https://forums.suse.com/showthread.php?2859-SLES11SP-and-never-version-of-Apache&p=15014#post15014](https://forums.suse.com/showthread.php?2859-SLES11SP-and-never-version-of-Apache&p=15014#post15014) for details on the CRIME fix for SLES.

Reegards,  
Jens

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [April 8, 2014, 7:44pm UTC](https://forums.suse.com/t/sles-sp3-and-apache-crime-exploit/25350/3 "2014-04-08T19:44:52Z")

</div>

This has come up before.

[https://forums.suse.com/archive/index.php/t-2105.html](https://forums.suse.com/archive/index.php/t-2105.html)

If you have done some testing and found your system still vulnerable,  
please post the tests done and system details to have it reproduced.

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![malcolmlewis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/malcolmlewis/32/11375_2.png) [@malcolmlewis](https://forums.suse.com/u/malcolmlewis)\
**Post date:** [April 8, 2014, 7:51pm UTC](https://forums.suse.com/t/sles-sp3-and-apache-crime-exploit/25350/4 "2014-04-08T19:51:09Z")

</div>

> [@](#):
>
> On Tue 08 Apr 2014 04:14:02 PM CDT, dennisdcs wrote:
> 
> Is there any fix for it? SLES is using and old version of Apache  
> (2.2.12) and I really don’t want to start having to compile things to  
> get a fixed version.

Hi  
Have you checked the apache2 changelog? Security fixes are backported,  
so the version of a package can be irrelevant.

AFAIK the code to fix is openssl;

```auto
rpm -qa --changelog |grep CVE-2012-4929
```

[https://bugzilla.novell.com/show\_bug.cgi?id=779952](https://bugzilla.novell.com/show_bug.cgi?id=779952)

–  
Cheers Malcolm Â°Â¿Â° SUSE Knowledge Partner (Linux Counter #276890)  
openSUSE 13.1 (Bottle) (x86\_64) GNOME 3.10.1 Kernel 3.11.10-7-desktop  
If you find this post helpful and are logged into the web interface,  
please show your appreciation and click on the star below… Thanks!

---

<div class="post-metadata">

**Author:** ![dennisdcs](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@dennisdcs](https://forums.suse.com/u/dennisdcs)\
**Post date:** [April 8, 2014, 8:33pm UTC](https://forums.suse.com/t/sles-sp3-and-apache-crime-exploit/25350/5 "2014-04-08T20:33:02Z")

</div>

Thanks for the replies. Apparently one of the patches fixed the issue.
