3 ms·
Does anyone know about apache?
by mwaitjmp 6y ago
Does anyone know about apache?
- throwaway823882 6y agoIt depends on the version of apache and openssl. Check the version of openssl that your apache binary is dependent on. All versions of 1.1.1 before 1.1.1k are vulnerable. ubuntu:~$ dpkg -s apache2-bin | grep ^Depends | sed -e 's/, /\n/g' | grep libssl | awk '{print $1}' | xargs dpkg -s | grep ^Version Version: 1.1.1j-1+ubuntu18.04.1+deb.sury.org+3 First try to just upgrade openssl on your system. Check the package's changelog (ex: http://changelogs.ubuntu.com/changelogs/pool/main/o/openssl/openssl_1.1.1f-1ubuntu4.2/changelog http://changelogs.ubuntu.com/changelogs/pool/main/o/openssl/...) to see if a fix has been backported into it, the version number may not indicate it. If you can't tell, try to install an older 1.0.x version. Then restart apache. (The magic of dynamic libraries... it'll be fun when Go's ssl library has a bug) If that doesn't work, try configuring SSLOptions -OptRenegotiate and then point ssllabs at it to see if reneg is disabled. If that doesn't work, recompile apache against a not-vulnerable version of openssl. Maybe the easiest way to do that is take the Dockerfile (https://github.com/docker-library/httpd/blob/master/2.4/Dockerfile https://github.com/docker-library/httpd/blob/master/2.4/Dock...), take out libssl-dev, compile a specific openssl version, then link against it.