Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #228462 > unrolled thread

Re: Information about security

Started byDan Ritter <dsr@randomstring.org>
First post2020-11-04 19:20 +0100
Last post2020-11-04 19:40 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: Information about security Dan Ritter <dsr@randomstring.org> - 2020-11-04 19:20 +0100
    Re: Information about security l0f4r0@tuta.io - 2020-11-04 19:40 +0100

#228462 — Re: Information about security

FromDan Ritter <dsr@randomstring.org>
Date2020-11-04 19:20 +0100
SubjectRe: Information about security
Message-ID<B7vy2-2gf-13@gated-at.bofh.it>
steph b wrote: 
> I recently audit my company and see in the server response the http server
> version (eg for debian buster : apache v2.4.38).
> 
> 1st I know that : this response must not contain this information.

ServerSignature Off
ServerTokens Prod


> 2nd When i search CVE about this version, i have a list of them here : https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-66/version_id-278546/Apache-Http-Server-2.4.38.html
> 
> Because i'm just a student, when i saw all this CVE, i wrote in my report
> "Update this apache version" but i was surprised to learn that the version
> was already uptodate !
> 
> So that is my question :
> 
> How to know exactly if this package is already update ?
> 
> I have seen in you FAQ: https://www.debian.org/security/faq#version
> 
> But for apache2, the command i know are :
> 
> > apache2 -v or httpd -v
> 
> Who return: Server version: Apache/2.4.38 (Debian)
> 
> 
> But how to compare exactly the version, or how to know which security patch
> are applied or missed for this package ?

zless "/usr/share/doc/apache2/changelog.Debian.gz"

The changelog will include appropriate CVEs.

-dsr- 

[toc] | [next] | [standalone]


#228463

Froml0f4r0@tuta.io
Date2020-11-04 19:40 +0100
Message-ID<B7vRn-2mq-7@gated-at.bofh.it>
In reply to#228462
Hi,

4 nov. 2020 à 19:15 de dsr@randomstring.org:

> steph b wrote: 
>
>> or how to know which security patch
>>
>> are applied or missed for this package ?
>>
> zless "/usr/share/doc/apache2/changelog.Debian.gz"
>
> The changelog will include appropriate CVEs.
>
+ https://security-tracker.debian.org/tracker/source-package/apache2

Best regards,
l0f4r0

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web