-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 SUMMARY cPanel, Inc. has released EasyApache 3.28.3 with Apache version 2.4.12. This release addresses vulnerabilities related to CVE-2014-3583, CVE-2014-3581, CVE-2014-8109, and CVE-2013-5704. We strongly encourage all Apache 2.4 users to upgrade to version 2.4.12. AFFECTED VERSIONS All versions of Apache 2.4 through 2.4.10. SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2014-3583 - MEDIUM Apache 2.4.12 Fixed bug in mod_proxy_fcgi related to CVE-2014-3583 CVE-2014-3581 - MEDIUM Apache 2/4/12 Fixed bug in mod_cache related to CVE-2014-3581 CVE-2014-8109 - MEDIUM Apache 2.4.12 Fixed bug in mod_lua related to CVE-2014-8109 CVE-2013-5704 - MEDIUM Apache 2.4.12 Fixed bug in the core related to CVE-2013-5704 SOLUTION cPanel, Inc. has released EasyApache 3.28.3 with an updated version of 2.4.12. Unless you have disabled EasyApache updates, EasyApache updates automatically. Run EasyApache to rebuild your profile with the latest version of Apache. REFERENCES http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3583 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3581 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8109 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-5704 http://www.apache.org/dist/httpd/CHANGES_2.4 -----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJUy/GkAAoJEJUhvtyr2U3fWcQP/1T4jL6rtIKdi1VTA3LQUHbo 6q4judfFYmMuRoVNMWKaG5tI48R8NkbA+a51URVsehdLrTW1L1iKTtP73cNHrj0O gG5pv8M9esbt4i6nmAfQ7Mv2nQIhzSd/R9Nwk0Ms18DBMSUzVJi131DPxH23UVPM ULfyrPwaNAC45a4XlsFWFNLDuPvftEGwWTaOQxQvpj0LjBhYXy3iLyDSoS5+mbKM k/equyooHd3o+QLBh1Ayd6zB9fwNd5RHiwt8wVfCSE8StqZLPmObSzE5j4mIq+Bq 68ZEftvngadMiPfDRuBWMA3nYdA8unJq8Xz5ka9e4CJ+yjWMyg6g10YwI2X16QLx +pneEFmTe6cmU9C+/IU1Njp7/ZZYMmkummy3zqO690TwRw65jkEHt5lpnEKzoAfB +iCHuWllEb8gVZc8rLHyEyxjgVeoTNvWKS1vYOJ2iBJS6p0ghWJFnVNyMWn6LOfA oBy8vF1OxN/TEuAy6vNJn73c5tocK0n8tZzlpYfFBY0a8FQmqXadT1PdkRHWZi8I 50aNOxOxVWgThPNyz8QX6ggu0GSFMNmCIHG132vm3vHdWiHCNfYqlWU9xo0JjuHg CeeE/nsOy/kXUpwlsW8xG9kNEflgbnQQzmJpbL1W7nZbim7/sjv7hE2UU1Ml69qg jfwhng0yQ9M+g5yhQKTT =TR9R -----END PGP SIGNATURE-----