Get our latest news

Blog & News

EasyApache 4 Update

  • 4 April 2019

The cPanel team has officially announced the release of an EasyApache 4 update. This release features a version update for ea-apache24 to 2.4.39, resolution to an issue with the installation of ea-liblsapi, and a solution for the premature stoppage of /scripts/ea-tomcat85.

cPanel has updated RPMs for EasyApache 4 with Apache version 2.4.39. This release addresses vulnerabilities related to CVE-2019-0197, CVE-2019-0196, CVE-2019-0211, CVE-2019-0217, CVE-2019-0215, and CVE-2019-0220. All users running on versions of Apache through 2.4.38 are strongly encouraged to upgrade to version 2.4.39.

All Nuagerie servers are automatically updated. However, for those that do not have automatic RPM cron updates enabled, please update your system with either yum update or through WHM’s Run System Update interface.

Changelog

ea-apache2

  • EA-8307: Update Apache to 2.4.39, drop 2.4.38

ea-apache2-config

  • EA-8305: Revert change in EA-8250

ea-liblsapi

  • EA-8300: Cannot reinstall ea-liblsapi because of conflicts with liblsapi

ea-tomcat85

  • EA-8241: /scripts/ea-tomcat85 prematurely dies if fs.protected_symlinks_create is enabled

This release includes security patches that have been issued for the following CVE (Common Vulnerabilities and Exposures), the details of which are included below.
 

Security Rating

The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs:

  • CVE-2019-0197 – Medium; Apache 2.4.39; Fixed bug in the http2 module related to CVE-2019-0197
  • CVE-2019-0196 – Medium; Apache 2.4.39; Fixed bug in the http2 module related to CVE-2019-0196
  • CVE-2019-0211 – Critical; Apache 2.4.39; Fixed bug in Unix MPMs related to CVE-2019-0211
  • CVE-2019-0217 – High; Apache 2.4.39; Fixed bug in mod_auth_digest related to CVE-2019-0217
  • CVE-2019-0215 – High; Apache 2.4.39; Fixed bug in the SSL module related to CVE-2019-0215
  • CVE-2019-0220 – Medium; Apache 2.4.39; Fixed bug related to CVE-2019-0220


More Information

For more information about all the changes to EasyApache 4, please make sure to visit the 2019 EasyApache 4 Changelog and the EasyApache 4 Release Notes. For a complete list of references for the vulnerabilities fixed, please go to the original cPanel announcement or make sure to contact us at any time.