Submitted by cron on Mon, 07/06/2020 - 09:00
Hi guys, I dont see security fixes for the following CVEs. Can you please add them?
CVE-2019-10092 CVE-2019-10098 CVE-2019-0220 CVE-2019-0217 CVE-2018-17199
Status:
Closed (fixed)
Hi guys, I dont see security fixes for the following CVEs. Can you please add them?
CVE-2019-10092 CVE-2019-10098 CVE-2019-0220 CVE-2019-0217 CVE-2018-17199
Comments
Submitted by andreychek on Mon, 07/06/2020 - 09:26 Comment #1
Thanks for passing the info! I'm passing this to Joe.
Note that to improve the lag we sometimes see with things like that, in CentOS 8 we came up with an alternative way of handling Apache so that it wouldn't actually need to be modified by us, so it uses the default package as provided by CentOS.
I appreciate that doesn't help you now, but just a note for the future!
Submitted by cron on Fri, 07/10/2020 - 03:59 Comment #2
Great thanks - that sounds much better. Are we talking days weeks or months for a CentOS 7 update?
Submitted by cron on Mon, 08/24/2020 - 16:52 Comment #3
Is there any update here? This was flagged again in our most recent vulnerability scan as an urgent issue.
Submitted by cron on Mon, 12/07/2020 - 06:46 Comment #4
This is really important guys. Apache is out of date and vulnerable until this is patched or a new version is ready. See vulnerabilities list for VirtualMin's version of apache: 2.4.6 https://www.cvedetails.com/version/161846/Apache-Http-Server-2.4.6.html
Version 2.4.6-95 is something CentOS 7 has upstream, right? We re-build httpd package based on upstream versions with suexec being the only difference.
Having a look at the package changelog it seems that it does resolves those CVEs :
Submitted by andreychek on Mon, 12/07/2020 - 13:34 Comment #6
Note that while Ilia is indeed correct, we do plan on pushing out an Apache package to keep it up to date with what RedHat/CentOS are offering. I spoke with Joe about that today, he expects to have that out soon!
Submitted by cron on Tue, 12/08/2020 - 07:29 Comment #7
Excellent thanks for the update Eric. We'll probably wait for the official release rather than trying to roll our own. I'd be worried about making a mess!
-97 package is in all repos.
Submitted by cron on Sat, 12/19/2020 - 12:39 Comment #9
Excellent thanks a lot Joe. Very much appreciated!
Submitted by IssueBot on Sat, 01/02/2021 - 12:42 Comment #10
Automatically closed - issue fixed for 2 weeks with no activity.