Hello!
Recently, after a security scan performed by our internal auditors, the vulnerability CVE-2011-3368 was found in our CloudLinux 6.8 (httpd-2.2.15-54.el6_8) installation.
My guess is that the scanner just saw the Apache version and assumed it was vulnerable, but I have confirmation that Red Hat backported the fix to Apache version 2.2.15-9 (https://access.redhat.com/security/cve/cve-2011-3368)
I think this should be already fixed, but I cant find any formal confirmation from CloudLinux team. Could someone from CloudLinux confirm this? I have my bosses after me to confirm it.
Thank you very much in advance for your time and help, regards...
Recently, after a security scan performed by our internal auditors, the vulnerability CVE-2011-3368 was found in our CloudLinux 6.8 (httpd-2.2.15-54.el6_8) installation.
My guess is that the scanner just saw the Apache version and assumed it was vulnerable, but I have confirmation that Red Hat backported the fix to Apache version 2.2.15-9 (https://access.redhat.com/security/cve/cve-2011-3368)
I think this should be already fixed, but I cant find any formal confirmation from CloudLinux team. Could someone from CloudLinux confirm this? I have my bosses after me to confirm it.
Thank you very much in advance for your time and help, regards...
Comment