Get our latest news

Blog & News

EasyApache 4 Maintenance Update

  • 5 December 2018

The cPanel team has updated RPMs for EasyApache 4 with OpenSSL version 1.0.2q. This release addresses several security vulnerabilities. All Nuagerie servers are automatically updated to reflect the patches but all OpenSSL users are strongly encouraged to check and update to version 1.0.2q. Unless you have enabled automatic RPM updates in your cron, update your system with either yum update or WHM’s Run System Update interface as soon as possible.

Affected Versions

All versions of OpenSSL through OpenSSL 1.0.2p

Security rating

The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs:

  • CVE-2018-5407 – MEDIUM; OpenSSL 1.0.2q; Fixed bug related to CVE-2018-5407
  • CVE-2018-0734 – MEDIUM; OpenSSL 1.0.2q; Fixed bug related to CVE-2018-0734

References


For more information about the update, please visit the release notes and changelog or contact us by opening a support ticket or by using our live chat feature.