-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 SUMMARY cPanel, Inc. has updated RPMs for EasyApache 4 with cURL version 7.61.0 and Apache 2.4.34 and released EasyApache 3.36.6 with cURL 7.61.0 and Apache 2.4.34 on July 18, 2018. This release addresses vulnerabilities related to CVE-2018-0500, CVE-2018-8011, and CVE-2018-1333. We strongly encourage all cURL users to update to version 7.61.0 and all Apache 2.4 users to upgrade to version 2.4.34. AFFECTED VERSIONS All versions of cURL through cURL 7.60.0 All versions of Apache through Apache 2.4.33 SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2018-0500 - MEDIUM cURL 7.61.0 Fixed bug related to CVE-2018-0500 CVE-2018-8011 - MEDIUM Apache 2.4.34 Fixed bug in mod_md module related to CVE-2018-8011 CVE-2018-1333 - MEDIUM Apache 2.4.34 Fixed bug in mod_Http2 module related to CVE-2018-1333 SOLUTION cPanel, Inc. has released updated RPMs for EasyApache 4 on July 18, 2018, with cURL version 7.61.0 and Apache version 2.4.34. Unless you have enabled automatic RPM updates in your cron, update your system with either yum update or WHM's Run System Update interface. cPanel, Inc. has released EasyApache 3.36.6 with cURL version 7.61.0 and Apache version 2.4.34. Unless you have disabled EasyApache updates, the EasyApache application updates to the latest version when launched. Run EasyApache to rebuild your profile with the latest version of Apache and PHP. REFERENCES https://nvd.nist.gov/vuln/detail/CVE-2018-0500 https://nvd.nist.gov/vuln/detail/CVE-2018-8011 https://nvd.nist.gov/vuln/detail/CVE-2018-1333 http://www.apache.org/dist/httpd/CHANGES_2.4 https://curl.haxx.se/changes.html -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIzBAEBCgAdFiEEtnCbTMb0IHf2mEGRlSG+3KvZTd8FAltPUs0ACgkQlSG+3KvZ Td+LXxAArunUHlBMYnZL1kUBtX9HNiLc0/4VJRYTvb8UOHC6ibGCLcFoA3/HYRJ1 6VYlykhLCaTXozf6nMd9PMuWTw7iQMR+5zOHMyOuUp6HTzoxuTpqo1Vdb6nazM9K DIjyJoMBx0OYG5Yb4YrFW2N7EfLHy/CiyJaHB/BbcwHcjHWqX7XL5ijduZVwvRnM g0++pv/hbw/muZR6lV0BY3w32YWYZLRnj/KYScisAFW08miqpCgh+rN6wfSwAC4E 10qD4bT7eWFEqQQxw1dx7YwFOzw1ricWNM0N+mTzvSMTT38qHIqABpExFqlkgNDg CeOVBn6aVyBuIZpiYjlf9Q8kvF2EbwUmAt6lyo3RYaZNfKYQXAoeqmZ6L/WnbMjE h3UHrAdV7joGQhshXXygVon6Jnfyo+1xs6geHfdA1y3Wvto2xZCYRWD5mK9tqnOv KmsV+2ilFHZ/K6ZOm+VJ3XA5g78zY+VUjhgjpfmhA0y57n4NeGfYx0jOn6RgkzWD rbJBE/eiuFhaLGMDtYyam/aaZFmkDX7+w817wij/lYuukXZOSyvUibGpdjqeL+Dw COEz2UExk8eClV6FvdEgVt2CqS8AvxLWFFGadLPwYdX9Tnj74KeHDwDYPSsnLeN8 KqVge7b4XDRIE6t1Sxt8nANObbppj1fKryio/kvBBZxD/Ib8HtM= =ExxD -----END PGP SIGNATURE-----