Page 1 of 2 12 LastLast
Results 1 to 15 of 20

Thread: New Apache Vulnerability

  1. #1
    Member
    Join Date
    Aug 2002
    Posts
    1,131

    Default New Apache Vulnerability

    This should probably be posted in Bugzilla, but I wanted to make sure that this was an issue that affected CPanel first. Looks like there is a new bug in Apache, specifically in mod_rewrite:

    http://secunia.com/advisories/21197

    The recommended solution is to upgrade to Apache 1.3.37. It would appear that easyapache is at 1.3.36. I wasn't sure if this affected CPanel's Apache (I would think that it does) or exactly how serious this is.

  2. #2
    Member
    Join Date
    Aug 2002
    Posts
    1,131

    Default

    This is listed in Bugzilla at:

    http://bugzilla.cpanel.net/show_bug.cgi?id=4433

  3. #3
    Member
    Join Date
    May 2003
    Location
    Acequias :: Granada :: España
    Posts
    210
    cPanel/WHM Access Level

    DataCenter Provider

    Thumbs down

    One more time, Cpanel Team, don't work for security on Cpanel/WHM.

    Expensive panel qith several problems of security issues.

    http://bugzilla.cpanel.net/show_bug.cgi?id=4433 has 48 hours.

    Security Advisore more 3 days.

    Explot calisfied CRITICAL.

    Please, Cpanel Team, more hard work on Security Issues.



    Advisorie of Apche Foundation:
    This issue has been rated as having important security impact by the Apache HTTP Server Security Team.onto http://www.apache.org/dist/httpd/Announcement1.3.html

  4. #4
    Member
    Join Date
    Aug 2002
    Posts
    1,131

    Default

    Just a note, I ran easyapache this morning on a test server and it appears that 1.3.37 is being compiled now. Someone else may want to verify this and make sure 1.3.37 is installing. I'm not aware of any official word from CPanel, so I might proceed with caution regarding the upgrade, but I did want to let everyone know that it appears 1.3.37 is available now.

  5. #5
    Member
    Join Date
    Feb 2003
    Posts
    205

    Default

    Yes apache 1.3.37 is now in easyapache

  6. #6
    Member
    Join Date
    Jan 2005
    Location
    /dev/null
    Posts
    770

    Default

    Under which tree is it available? EDGE?

  7. #7
    Member
    Join Date
    Nov 2004
    Location
    alberta
    Posts
    100

    Default

    thats not the only bug i discovered bugs in openssl and can be exploted to gain root level access.

    oh well

    hope they fix it

  8. #8
    cPanel Partner NOC cPanel Partner NOC Badge myusername's Avatar
    Join Date
    Mar 2003
    Location
    chown -R us.us *yourbase*
    Posts
    713
    cPanel/WHM Access Level

    DataCenter Provider

    Default

    Might as well add php 4.4.3 support to the gripes list:

    http://secunia.com/advisories/21328/
    GlowHost.com | Professional Managed Web Hosting Since 2002.
    >> Fully Managed Dedicated, Cloud VDS, Reseller & Semi-Dedicated
    >> Cloud Servers for Enterprise

  9. #9
    Member
    Join Date
    Aug 2002
    Posts
    1,131

    Default

    As fas as I know the Apache version is indepdent of your CPanel build. So it doesn't matter what CPanel tree you are using, easyapache will install the same version of Apache for each build. I may be wrong in that regard. At any rate, I'm using Release and 1.3.37 is in it.

  10. #10
    Member
    Join Date
    Jun 2003
    Location
    Florida
    Posts
    37

    Default

    I'm on the stable release tree and it will only compile 1.3.36. Any way to get 1.3.37 into the stable release tree?

  11. #11
    Member
    Join Date
    Jun 2003
    Location
    Florida
    Posts
    37

    Default

    Sorry, I guess I should have been more clear. I'm using the stable version, NOT release.

  12. #12
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by gahelm
    I'm on the stable release tree and it will only compile 1.3.36. Any way to get 1.3.37 into the stable release tree?
    Just re-compiled Apache on one of our client's servers and I got:

    Server version: Apache/1.3.37 (Unix)
    Server built: Aug 3 2006 16:46:36
    Server: cPanel [10.8.2-RELEASE_119]
    Andy Reed
    CCNA, RHCE, and Ubuntu Technologist
    ServerTune.com

  13. #13
    Member
    Join Date
    Jun 2003
    Posts
    19

    Default

    Hey all,

    Does is cause any problems if you were to just manually configure any software like apache or php together manually rather then using cPanel? Will cPanel have any issues?

    Thanks,
    Russ

  14. #14
    Member
    Join Date
    Aug 2002
    Posts
    1,131

    Default

    Quote Originally Posted by MPCN_Russ1
    Hey all,

    Does is cause any problems if you were to just manually configure any software like apache or php together manually rather then using cPanel? Will cPanel have any issues?

    Thanks,
    Russ
    I don't know about Apache, but I always compile PHP separately. This is mainly because I want to do more customization to my PHP installs.

    One quick tidbit, if you run easyapache, you can unselect PHP so that it is not checked, then easyapache won't compile PHP. Your PHP will continue to work and easyapache will only compile Apache. This can greatly improve the amount of time spent upgrading Apache. One word of caution, if you are using phpSuExec, you must check that box in easyapache. You don't have to select PHP, but you do have to check the phpSuExec option. This is because the phpSuExec wrapper depends on some patches applied to Apache's source code, and selecting this option tells easyapache to apply those patches.

    Hope this helps.

  15. #15
    Member
    Join Date
    Sep 2003
    Posts
    126

    Default

    Quote Originally Posted by myusername
    Might as well add php 4.4.3 support to the gripes list:

    http://secunia.com/advisories/21328/
    Yes, vote for php 4.4.3 !

    -FL-

Page 1 of 2 12 LastLast

Similar Threads

  1. cPanel Vulnerability?
    By Speedy059 in forum Security
    Replies: 1
    Last Post: 06-21-2011, 06:55 PM
  2. New IE Vulnerability
    By markb14391 in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 12-16-2008, 07:36 PM
  3. Server Compromised: Apache or PHP vulnerability
    By stugster in forum cPanel & WHM Discussions
    Replies: 6
    Last Post: 09-07-2006, 09:55 PM
  4. apache 1.3.36 vulnerability found / 1.3.37 update?
    By aww in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 08-02-2006, 03:46 AM