[Spacewalk-list] HTTPD Version

Gerald Vogt vogt at spamcop.net
Sat Dec 8 07:43:37 UTC 2018


On 07.12.18 22:49, Snyder, Alexander wrote:
> I’m currently using Spacewalk 2.7, and it comes bundled with 
> /httpd24-httpd-2.4.27/, which is affected by “*CVE-2017-15715*”.

What makes you think it is bundled with spacewalk? As far as I can see 
Spacewalk does not include the web server on RHEL7/CentOS7. You have 
installed the httpd from the RedHat/CentOS SCL. Update it from the SCL.

Our spacewalk installation only depends on the standard httpd package 
which comes from the standard repositories. It makes me wonder why you 
have installed http24-httpd from the SCL on EL7 to begin with. I don't 
see why you would need that. The httpd rpm from the standard 
repositories should work.

And if you enable the SCL repositories for installation you should not 
remove them afterwards for obvious reasons.

> I’m trying to find the httpd24-httpd version bundled with Spacewalk 2.80.

Spacewalk 2.8 uses the standard httpd rpms from the standard 
repositories. It's not bundled.

> Would it be suggested to upgrade to 2.8, or should upgrading with 
> /httpd24-httpd-2.4.34-7.el7.x86_64.rpm/ be sufficient.

I would suggest either enable the SCL repo again or use the standard 
httpd instead.

-Gerald


> 
> Any help on that is appreciated.
> 
> Thank you.
> 
> *Alexander Snyder***|*  Linux Systems Administrator*
> 
> *Direct*480.426.2081
> *After Hours: *480.656.6969
> *Email*alexander.snyder2 at earlywarning.com 
> <mailto:alexander.snyder2 at earlywarning.com>
> 
> www.earlywarning.com <http://www.earlywarning.com/>
> 
> cid:image001.jpg at 01D46A16.1B20B4A0
> 
> cid:image002.jpg at 01D46A16.1B20B4A0Please consider the environment before 
> printing this message
> 
> This email transmission may contain confidential and/or private 
> information, which is the property of the sender. The information in 
> this email or attachments thereto is intended for the attention and the 
> use only of the addressee. If you are not the intended recipient, you 
> are hereby notified that any disclosure, copying, or distribution of the 
> contents of this email transmission, or the taking of any action in 
> reliance thereon or pursuant thereto, is strictly prohibited. Should you 
> have received this email in error, please contact the sender and delete 
> and destroy all copies of the original message.
> 
> 
> _______________________________________________
> Spacewalk-list mailing list
> Spacewalk-list at redhat.com
> https://www.redhat.com/mailman/listinfo/spacewalk-list
> 




More information about the Spacewalk-list mailing list