You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@httpd.apache.org by Sunhux G <su...@gmail.com> on 2019/04/06 14:59:06 UTC

[users@httpd] CVE-2019-0211/0215/0217

Are above CVEs affecting Apache httpd (ie web servers) 2.4.x  only
& other lower versions (eg: our Solaris 10's  Apache/2.0.63) are not
affected?

Can point me to where to get the patches for RHEL7/RHEL6
in Red Hat support portal or anywhere else that's reliable??

Sun

Re: [users@httpd] Re: CVE-2019-0211/0215/0217

Posted by Yehuda Katz <ye...@ymkatz.net>.
The distributions like RedHat, Debian, Ubuntu, etc. lock the version of
their software packages when they release any specific version of their OS
and they are responsible to backport any security or bug fixes.

For example, you can see Debian's tracker here:
https://security-tracker.debian.org/tracker/CVE-2019-0211
They append their own release number to the end of the HTTPD version to
show that they fixed the bug (2.4.25-3+deb9u6 to deb9u7).
Ubuntu says they fixed the issues in 2.4.29-1ubuntu4.6

- Y

On Sun, Apr 7, 2019 at 3:43 AM Dan Ehrlich <da...@ehrlichserver.com.invalid>
wrote:

> I’ve seen a few CVEs now that are low level but pretty much effect every
> version from 2.4.30ish and back.
>
> The default Apache versions in the Debian and Ubuntu repos are 2.4.25 and
> 2.4.29 respectively.
>
> QUESTIONS:
> 1. Anyway to move the versions up (assuming I didn’t miss something) ?
> 2. Happy to help / take on task if someone can point me in the right
> direction
>
>
> On Apr 6, 2019, at 11:14 PM, Sunhux G <su...@gmail.com> wrote:
>
> Also,
> can we safely say CVE-2019-0217 & CVE-2019-0215 affects "2.4.17 through
> 2.4.38 with MPM event, worker or prefork" only (just like CVE-2019-0211)?
>
> How do I check if we have "MPM event, worker or prefork" in our Apache?
>
> On Sat, Apr 6, 2019 at 10:59 PM Sunhux G <su...@gmail.com> wrote:
>
>>
>> Are above CVEs affecting Apache httpd (ie web servers) 2.4.x  only
>> & other lower versions (eg: our Solaris 10's  Apache/2.0.63) are not
>> affected?
>>
>> Can point me to where to get the patches for RHEL7/RHEL6
>> in Red Hat support portal or anywhere else that's reliable??
>>
>> Sun
>>
>

Re: [users@httpd] Re: CVE-2019-0211/0215/0217

Posted by Dan Ehrlich <da...@ehrlichserver.com.INVALID>.
I’ve seen a few CVEs now that are low level but pretty much effect every version from 2.4.30ish and back. 

The default Apache versions in the Debian and Ubuntu repos are 2.4.25 and 2.4.29 respectively.

QUESTIONS:
1. Anyway to move the versions up (assuming I didn’t miss something) ?
2. Happy to help / take on task if someone can point me in the right direction 


> On Apr 6, 2019, at 11:14 PM, Sunhux G <su...@gmail.com> wrote:
> 
> Also, 
> can we safely say CVE-2019-0217 & CVE-2019-0215 affects "2.4.17 through 2.4.38 with MPM event, worker or prefork" only (just like CVE-2019-0211)?
> 
> How do I check if we have "MPM event, worker or prefork" in our Apache?
> 
> 
>> On Sat, Apr 6, 2019 at 10:59 PM Sunhux G <su...@gmail.com> wrote:
>> 
>> Are above CVEs affecting Apache httpd (ie web servers) 2.4.x  only 
>> & other lower versions (eg: our Solaris 10's  Apache/2.0.63) are not
>> affected?
>> 
>> Can point me to where to get the patches for RHEL7/RHEL6
>> in Red Hat support portal or anywhere else that's reliable??
>> 
>> Sun

[users@httpd] Re: CVE-2019-0211/0215/0217

Posted by Sunhux G <su...@gmail.com>.
Also,
can we safely say CVE-2019-0217 & CVE-2019-0215 affects "2.4.17 through
2.4.38 with MPM event, worker or prefork" only (just like CVE-2019-0211)?

How do I check if we have "MPM event, worker or prefork" in our Apache?

On Sat, Apr 6, 2019 at 10:59 PM Sunhux G <su...@gmail.com> wrote:

>
> Are above CVEs affecting Apache httpd (ie web servers) 2.4.x  only
> & other lower versions (eg: our Solaris 10's  Apache/2.0.63) are not
> affected?
>
> Can point me to where to get the patches for RHEL7/RHEL6
> in Red Hat support portal or anywhere else that's reliable??
>
> Sun
>

Re: [users@httpd] Re: CVE-2019-0211/0215/0217

Posted by William A Rowe Jr <wr...@rowe-clan.net>.
In general, problems which stretch back to the initial 2.4.1 or commonly
deployed 2.4.3 might also affect 2.2.x or 2.0.x. As users have had almost a
decade to adjust and these versions are EOL, the project seems unlikely to
care, and notices are everywhere that the old flavors are no longer
evaluated for the impact of any defects, security or otherwise. Vendors who
support older flavors are on their own to make such evaluations themselves.

And in general, when a later, specific flavor of 2.4.x (e.g. 2.4.17) is
cited as the first version impacted, that version is expected to be the one
where a defect was introduced.

There is the edge case that a problem could exist, then be fixed or masked
sometime before 2.4.1, and later be reintroduced during 2.4.x, but the
rules above should generally apply.

On Sun, Apr 7, 2019, 02:38 @lbutlr <kr...@kreme.com> wrote:

> On 6 Apr 2019, at 08:59, Sunhux G <su...@gmail.com> wrote:
> > Are above CVEs affecting Apache httpd (ie web servers) 2.4.x  only
> > & other lower versions (eg: our Solaris 10's  Apache/2.0.63) are not
> > affected?
>
> The CVE lists, explicitly, what versions are affected.
>
> "The flaw was discovered by Charles Fol and impacts all Apache HTTP Server
> releases from 2.4.17 to 2.4.38. The issue has been addressed with the
> release of Apache httpd 2.4.39"
>
> Also, as you should be aware, Apache 2.0 and Apache 2.2 are both
> End-of-life and not supported any longer.
>
>
> --
> Love is like oxygen / You get too much / you get too high / Not enough
> and you're gonna die
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
> For additional commands, e-mail: users-help@httpd.apache.org
>
>

[users@httpd] Re: CVE-2019-0211/0215/0217

Posted by "@lbutlr" <kr...@kreme.com>.
On 6 Apr 2019, at 08:59, Sunhux G <su...@gmail.com> wrote:
> Are above CVEs affecting Apache httpd (ie web servers) 2.4.x  only 
> & other lower versions (eg: our Solaris 10's  Apache/2.0.63) are not
> affected?

The CVE lists, explicitly, what versions are affected.

"The flaw was discovered by Charles Fol and impacts all Apache HTTP Server releases from 2.4.17 to 2.4.38. The issue has been addressed with the release of Apache httpd 2.4.39"

Also, as you should be aware, Apache 2.0 and Apache 2.2 are both End-of-life and not supported any longer.


-- 
Love is like oxygen / You get too much / you get too high / Not enough
and you're gonna die


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org