Security Basics mailing list archives

Re: mod_ssl vulnerabitly


From: "Tim Greer" <chatmaster () charter net>
Date: Mon, 9 Jun 2003 09:58:34 -0700

This didn't "just come out", it's been out for months. Information is on
modssl.org's web site. Cpanel just sat back and took forever to bother to
upgrade and now their admin interface is warning you about something that
should have been upgraded months ago. This isn't the only thing that needs
to be upgraded,  but maybe they'll get around to those as well. I recommend
taking matters into your own hands and keeping up to date on these issues
and upgrading them yourself and bypassing the Cpanel install scripts, or
this is what can happen.
--
Regards,
Tim Greer  chatmaster () charter net
Server administration, security, programming, consulting.


----- Original Message -----
From: "H. J." <advenracer88 () yahoo com>
To: <security-basics () securityfocus com>
Sent: Saturday, June 07, 2003 2:52 PM
Subject: mod_ssl vulnerabitly


Does anyone know what the mod_ssl vulnerbility is that
just came out?
mod_ssl 2.8.12 Insecure

You are running an insecure apache setup. You should
run /scripts/easyapache and upgrade to a newer version
as soon as possible to avoid your system being compromised.

__________________________________
Do you Yahoo!?
Yahoo! Calendar - Free online calendar with sync to Outlook(TM).
http://calendar.yahoo.com

--------------------------------------------------------------------------
-
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.

Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.

Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
--------------------------------------------------------------------------
--



---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
     
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
          
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------


Current thread: