ClearFoundation Tracker - ClearOS
View Issue Details
0021651ClearOShttpdpublic2018-10-01 11:402019-02-23 15:11
dloper 
dloper 
normalminoralways
closedsuspended 
7.4.0 
7.6.0 Updates 
0021651: Vulnerability for CVE-2016-4975
CVE-2016-4975 creates a vulnerability in httpd and webconfig-httpd. This old bug has not been addressed by Redhat or CentOS communities at this time.

https://bugzilla.redhat.com/show_bug.cgi?id=1375968 [^]

https://access.redhat.com/security/cve/cve-2016-4975 [^]

We may need to fork if upstream is not forthcoming with a fix for this issue.
Redhat has backported this fix into https://access.redhat.com/errata/RHSA-2018:2185 [^]

But has not ported this to httpd yet.
No tags attached.
Issue History
2018-10-01 11:40dloperNew Issue
2018-10-01 12:10user2Statusnew => confirmed
2018-10-30 18:07user2Severitymajor => minor
2018-10-30 18:08user2Target Version7.5.0 Updates => 7.6.0 Updates
2019-02-23 15:11dloperNote Added: 0009401
2019-02-23 15:11dloperStatusconfirmed => closed
2019-02-23 15:11dloperAssigned To => dloper
2019-02-23 15:11dloperResolutionopen => suspended

Notes
(0009401)
dloper   
2019-02-23 15:11   
Migrated to: https://gitlab.com/clearos/clearfoundation/app-web-server/issues/3 [^]