Skip to main content
Early Access
— Mondoo Vulnerability Intelligence is currently in preview.
Vulnerability Intelligence
Login
Get Demo
SUSE-SU-2025:4518-1 | Mondoo Vulnerability Intelligence
Back to search
SUSE-SU-2025:4518-1
UNKNOWN
Security update for apache2
Published Dec 23, 2025
Modified 3 weeks ago
Fix available
Details
This update for apache2 fixes the following issues:
CVE-2025-55753: Fixed mod_md (ACME) unintended retry intervals (bsc#1254511)
CVE-2025-65082: Fixed CGI environment variable override (bsc#1254514)
CVE-2025-58098: Fixed Server Side Includes adding query string to #exec cmd=... (bsc#1254512)
CVE-2025-66200: Fixed mod_userdir+suexec bypass via AllowOverride FileInfo (bsc#1254515)
Affected Packages
SUSE:Linux Enterprise Module for Basesystem 15 SP7
apache2
Fixed in:
2.4.62-150700.4.9.1
SUSE:Linux Enterprise Module for Basesystem 15 SP7
apache2-prefork
Fixed in:
2.4.62-150700.4.9.1
SUSE:Linux Enterprise Module for Package Hub 15 SP7
apache2-event
Fixed in:
2.4.62-150700.4.9.1
SUSE:Linux Enterprise Module for Server Applications 15 SP7
apache2-devel
Fixed in:
2.4.62-150700.4.9.1
SUSE:Linux Enterprise Module for Server Applications 15 SP7
apache2-utils
Fixed in:
2.4.62-150700.4.9.1
SUSE:Linux Enterprise Module for Server Applications 15 SP7
apache2-worker
Fixed in:
2.4.62-150700.4.9.1
References
REPORT
https://bugzilla.suse.com/1254511
REPORT
https://bugzilla.suse.com/1254512
REPORT
https://bugzilla.suse.com/1254514
REPORT
https://bugzilla.suse.com/1254515
WEB
https://www.suse.com/security/cve/CVE-2025-55753
WEB
https://www.suse.com/security/cve/CVE-2025-58098
WEB
https://www.suse.com/security/cve/CVE-2025-65082
WEB
https://www.suse.com/security/cve/CVE-2025-66200
ADVISORY
https://www.suse.com/support/update/announcement/2025/suse-su-20254518-1/
Upstream
CVE-2025-55753
CVE-2025-58098
CVE-2025-65082
CVE-2025-66200
Related
CVE-2025-55753
CVE-2025-58098
CVE-2025-65082
CVE-2025-66200
Ecosystems
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Package Hub 15 SP7
SUSE Linux Enterprise Module for Server Applications 15 SP7
Timeline
Published
Dec 23, 2025
Modified
Dec 23, 2025