ClearOS Documentation

×

Warning

301 error for file:https://clearos.com/dokuwiki2/lib/exe/css.php?t=dokuwiki&tseed=82873f9c9a1f5784b951644363f20ef8

User Tools

Site Tools


This entry from Security Metrics is followed up with the following CVE:

ClearCenter response

Short response

This CVE is addressed in a backported fix to ClearOS. ClearOS 5.x systems running the latest updates are not vulnerable. ClearOS 6.x systems running the latest updates are not vulnerable.

Long response

Previous fixes to ClearOS addressed this issue. However, ClearOS does not increment version numbers in order to maintain dependencies between subsystems. The audit system has not taken into account ClearOS minor version numbers which correctly represent the fix to the system.

ClearOS has backported fixes to this problem. Updated versions of ClearOS 5.x are not vulnerable to this issue. Updated versions of ClearOS 6.x are not vulnerable to this issue.

Resolution

To verify that you are running the a version of ClearOS that is not susceptible to this attack run your updates. Alternately, run the following to determine if they are already installed:

rpm -qi httpd

Pay attention to the Version and Release lines and compare to the following:

  • ClearOS 5.x httpd version: 2.2.3
    • Fixed in release: 63.el5
  • ClearOS 6.x httpd version: 2.2.15
    • Fixed in release: 15.el6

If your release number is the same or higher. This issue does NOT affect you.

To fix this issue, run updates:

yum update
content/en_us/kb_3rdparty_security_metrics_apache_http_server_httponly_cookie_information_disclosure.txt · Last modified: 2015/02/28 20:52 (external edit)

https://clearos.com/dokuwiki2/lib/exe/indexer.php?id=content%3Aen_us%3Akb_3rdparty_security_metrics_apache_http_server_httponly_cookie_information_disclosure&1558454585