/** * This is the notes section. CVE documents should ONLY be created by employees of ClearCenter with the authority to make statements on behalf of the company. If you have content that would be useful to the statement, please contact ClearCenter. */
'In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.'
This issue affects ClearOS 7 but does not affect any version of ClearOS 6.
This issue was fixed in the backported fixes of versions of:
This issue was fixed during the maintenance cycle of ClearOS 7. No version of ClearOS 6 has ever been affected by this vulnerability. ClearOS systems that are up to date do not suffer from this vulnerability. Some vulnerability scanning software may report this bug because their only method for determining the issue is to check the http version number since the exploit requires specific web configurations and has not other means for testing vulnerability. In ClearOS, version numbers stay consistent through the product's life-cycle and will produce a false positive on this issue if the testing software considers only the http version and not the ClearOS patch level.
If you are running ClearOS 7, please ensure that you are running the latest updates:
You may also validate your version by running:
rpm -qi httpd
You should validate that you are running: