Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Tue Sep 09, 2014 9:46 am 
Offline
Newbie

Joined: Tue Jul 22, 2014 12:40 pm
Posts: 4
Hi,

I've had a vulnerability scan run against my web server (for PCI DSS compliance) and they've come back with a handful of vulnerabilities. My Linode is running Ubuntu 12.04 LTS and Apache 2.2.22. It appears that most of the CVE's that were found on my server are fixed in later releases of Apache. Running apt-get update / apt-get upgrade --show-upgraded doesn't show anything new to install. I've seen on the apache website that 2.2.29 is the latest version and I assume this will fix all of the vulnerabilities on my server. How do I upgrade from 2.2.22 to 2.2.29?

Thanks,
Mark.

(edit: updated the post title to make this more useful to others who come across the same issue in future!)


Last edited by chipfat on Tue Sep 09, 2014 4:32 pm, edited 1 time in total.

Top
   
 Post subject: Re: Apache Upgrade
PostPosted: Tue Sep 09, 2014 10:25 am 
Offline
Senior Newbie
User avatar

Joined: Thu Oct 23, 2008 9:25 pm
Posts: 16
Website: http://bofh.hosscomm.com
Your apache may already be 'patched'. Depending on the vulnerabilities listed by your test... they may not test for the patch... the test may just be looking for the 'version'

:arrow: http://serverfault.com/questions/533206 ... -to-apache
also
:arrow: http://serverfault.com/questions/568456 ... e2-for-pci

hope this helps. :)


Top
   
 Post subject: Re: Apache Upgrade
PostPosted: Tue Sep 09, 2014 4:27 pm 
Offline
Newbie

Joined: Tue Jul 22, 2014 12:40 pm
Posts: 4
Yes! Thanks for that. The second one of those links was spot on - exactly the vuln's the PCI scanner is claiming and, yes, on checking the "Detailed" section of my report, the "evidence" is simply version numbers. My Linode has apache2 2.2.22-1ubuntu1.7 and all the vulns were fixed in either 2.2.22-1ubuntu1.3 or 2.2.22-1ubuntu1.4.

Cheers MotoHoss!


Top
   
PostPosted: Tue Sep 09, 2014 10:23 pm 
Offline
Senior Member

Joined: Fri May 02, 2008 8:44 pm
Posts: 1121
Try changing "ServerTokens" to "Prod" (this hides the version number) and see how the scanner handles that :P


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group