Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
Expand all | Collapse all

httpd and sqlite security vulnerability fixes

  • 1.  httpd and sqlite security vulnerability fixes

    Posted Tue February 13, 2018 12:24 AM

    Originally posted by: sanket


     

    httpd-2.4.29 and sqlite-3.21.0 are now available on AIX toolbox.

    https://public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/RPMS/ppc/httpd/httpd-2.4.29-1.aix6.1.ppc.rpm

    https://public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/RPMS/ppc/sqlite/sqlite-3.21.0-1.aix6.1.ppc.rpm

     

    This version of http has fix for following security vulnerability.

    CVE-2017-9798

     

    This version of sqlite has fix for following security vulnerability.

    CVE-2017-13685

     

    You can also use YUM to update to these versions of httpd and sqlite from AIX toolbox repository

     

    Thanks

     

     

    #AIXOpenSource
    #AIX-Open-Source-Software


  • 2.  Re: httpd and sqlite security vulnerability fixes

    Posted Mon June 11, 2018 02:04 PM

    Originally posted by: HJHJ


    Can we please get an update to 2.4.33? 

     

    2.4.29 has been flagged by our security scanners as being vulnerable. Thanks.


    #AIXOpenSource
    #AIX-Open-Source-Software


  • 3.  Re: httpd and sqlite security vulnerability fixes

    Posted Tue June 12, 2018 05:10 AM

    Originally posted by: sanket


    Yes.. we are aware of the security vulnerabilities on 2.4.29.

    We are working on 2.4.33 and soon we will publish that.


    #AIX-Open-Source-Software
    #AIXOpenSource


  • 4.  Re: httpd and sqlite security vulnerability fixes