Re: help in patching
peredina <[email protected]> Wed, 26 Jun 2002 07:57:11 -0400
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <[email protected]> |
Yes, that is the version I am running. Thanks for you assistance. Curt Mark J Cox wrote: >>I have tested the tool with patched, and unpatched versions of 1.3.20 >>(setting both generic banners and default banners), and it does not >>appear to be looking at the banners. > > > Attached is the response I got from eEye about this issue; however please > note that an unpatched Stronghold 3.1 build 3016 is vulnerable to this > security issue, regardless of the output of this tool. > > Cheers, Mark > > Date: Mon, 24 Jun 2002 16:29:55 -0700 > From: eEye Support <[email protected]> > To: Mark J Cox <[email protected]> > Subject: RE: false positives in Apache Scanning Tool? Or patches aren't > working? > > We have updated the tool to v1.02, so please try it and see if it resolves > the issue. > > Sincerely, > > Technical Support Team > eEye Digital Security > http://www.eeye.com/support > IF YOU ARE NOT USING THE WEB SUPPORT FORM, > RESPONSE MAY BE SLOWER DUE TO MANUAL PROCESSING! > http://www.eeye.com/support > > > >>-----Original Message----- >>From: Mark J Cox [mailto:[email protected]] >>Sent: Friday, June 21, 2002 10:55 AM >>Subject: Re: false positives in Apache Scanning Tool? Or patches aren't >>working? >> >> >>The Red Hat RPM's contain a backported version of the security patch >>rather than upgrading to Apache 1.3.26 that has been verified to fix the >>vulnerability. My guess is that the Apache scanner simply looks at the >>server version string returned by the server to make it's assesment of if >>a site is vulnerable or not, since the server version string has not >>changed to Apache 1.3.26 this is why it is giving you a false positive. >> >>Cheers, Mark >>-- >>Mark J Cox / Red Hat / OpenSSL / Apache Software Foundation >>[email protected] // T: +44 798 061 3110 // F: +44 870 1319174 >> >> >> >> > > > > > > _______________________________________________ > Stronghold-users mailing list > [email protected] > https://listman.redhat.com/mailman/listinfo/stronghold-users