-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 SUMMARY cPanel, Inc. has released EasyApache 3.34.10 with Apache version 2.4.25. This release addresses vulnerabilities related to CVE-2016-0736, CVE-2016-2161, CVE-2016-5387, CVE-2016-8740, and CVE-2016-8743. We strongly encourage all Apache 2.4 users to upgrade to version 2.4.25. AFFECTED VERSIONS All versions of Apache 2.4 through version 2.4.23 SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2016-0736 - MEDIUM Apache 2.4.25 Fixed bug in mod_session_crypto related to CVE-2016-0736 CVE-2016-2161 - MEDIUM Apache 2.4.25 Fixed bug in mod_auth_digest related to CVE-2016-2161 CVE-2016-5387 - HIGH Apache 2.4.25 Fixed bug in Core related to CVE-2016-5387 CVE-2016-8740 - HIGH Apache 2.4.25 Fixed bug in mod_http2 related to CVE-2016-8740 CVE-2016-8743 - MEDIUM Apache 2.4.25 Fixed whitespace parsing defects related to CVE-2016-8743 SOLUTION cPanel, Inc. has released EasyApache 3.34.10 with an updated version of Apache 2.4.25. Unless you have disabled EasyApache updates, the EasyApache application updates to the latest version when launched. Run EasyApache to rebuild your profile with the latest version of PHP. REFERENCES https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-8740 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5387 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2161 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0736 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-8743 http://www.apache.org/dist/httpd/CHANGES_2.4.25 -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJYblxoAAoJEJUhvtyr2U3f+Q8QAL7J0YSyj/EloOE1BKx8eAAS FWxT28c6hkU+tdmwcCYf30myuLDsL1RijUImI4x9ADPVM5kAqCc/eqsA62JICMRE KWxa43PBBpmZA9TWKN+kJ26q2QHiS2SpFbXBf1u8Vtcu5up/w2B+7jwvvYVRhgnq A2jx/cePHNAwxOr4pMdx3pzns3MxSuYHs+57G0AHzXTFKiCsZRcsnOxXIAf/t4d8 G9YdxL2ccF2ow/HCs99T7MnaGydzz2zzHeCV9wqhwcsxnf2ds/l56arbDl7LwiQJ 6wL8kyQ8761YKaVLhhH8S6jCGawRsL21sNpnml/kwxX+Qnjefmln0MZVQjo76f8v oBvrI4o+Nh4/Den4OzxTZvcOkLMjbt0k3S+/jJMlT0JgwYdmYcL5UOB3jjcrQvfD GSNLGZCq6DGt99XhuXmVxsw+FSwlT8lCMJjlxkxeWVMiTGGFo96ZhaqtMlnB6D3F S+rMNbjONTIco9eBW26VSdyfX7kyFrH5SVhPR3Qj8YQ15h8OmfkWI60vSFxyOhfu GKztylwUGdx9K4O6xxF7VGu0T7Vt9FmqZlRWsH6oHHgnF7aXU8+ALDJjsa2WwY9F tnthq/2jeqoCROPq0UR8YMXs/IJs0QHFm+LFHxMEVUf7XOT4qtTxtsv9u3n5UfPg biZiyB+NiXu3HSBl9oXL =O+Iy -----END PGP SIGNATURE-----