Home > linux > How Do I Update Apache to 2.2.24 On AWS Instance

How Do I Update Apache to 2.2.24 On AWS Instance

March 18Hits:4
Advertisement

I have a website hosted on an Amazon AMI Linux instance.

We had a PCI Scan recently and we failed the scan because we have Apache 2.2.23 installed, and apparently it contains vulnerabilities that have been since fixed on 2.2.24.

I did a sudo yum update but after checking the apache version using httpd -v it still reports 2.2.23. A yum info httpd also confirms that the repository version is 2.2.23

Is there any way to force yum to update to the latest version or to add a custom repository pointing to the latest apache release? I am a developer and I don't have a lot of experience hosting on linux, so I am a little bit stumped as to what to do.

Any tips will be appreciated, thanx!

Answers

Take a step back. The PCI scanner is blindly relying on version numbers and isn't taking into account that the vendor (which is eventually Red Hat) backports patches. Find out the exact vulnerability (get the CVE) and then use rpm -q --changelog httpd (or go to http://cve.mitre.org/cve/cve.html and https://access.redhat.com/security/updates/ ) to see if the fix has been backported. It is annoying to do; thank your lazy PCI QSA for the work.

I strongly recommend against installing from source. It breaks package management and you now become responsible for keeping apache up to date which is more annoying than verifying the backporting of fixes.

Why not just install Apache 2.4.3?

yum install httpd24

Related Articles

  • How Do I Update Apache to 2.2.24 On AWS InstanceMarch 18

    I have a website hosted on an Amazon AMI Linux instance. We had a PCI Scan recently and we failed the scan because we have Apache 2.2.23 installed, and apparently it contains vulnerabilities that have been since fixed on 2.2.24. I did a sudo yum upda

  • Do I need to update Apache on CentOS 5.6?August 8

    Running: CentOS 5.6 I have been on Google and reading all weekend on trying to update Apache to the latest version (2.2.19), but am now a little confused. Does the CentOs version 2.2.3 include backported security patches and so "yum update" will

  • Impact of updating ApacheMay 8

    I'm trying to sort out updating server software to fix some found security issues, but before I do, I need to make sure that this won't affect the website that's currently running. I know for example updating PHP can cause issues with deprecated func

  • Update Apache 2.2 to Apache 2.4February 19

    I have ISPConfig latest version on Debian 7, but i want to update apache to 2.4, how can i do it a try apt-get install apache2 but sites stop working after that? --------------Solutions------------- The steps are: 1) Do a distribution upgrade to debi

  • Update Apache 2.2.22 to 2.2.25October 9

    I need to update Apache to version 2.2.25 on ubuntu 13.04 I have tried installing the update from apt-get but the package is showing as 2.2.22 Can anyone help? --------------Solutions------------- You can't install yet Apache 2.2.25 using apt-get bec

  • Subdomains returning HTTP 403 after updating Apache from 2.2 to 2.4November 22

    After an operating system upgrade which involved updating Apache from 2.2 to 2.4, I'm now getting 403s trying to access http://files.fierydragonlord.com/ and http://status.fierydragonlord.com/. However, http://www.fierydragonlord.com works. What's go

  • Easiest way to update Apache, MySQL & PHP on VPS October 21

    This question already has an answer here: How do I install latest PHP in supported Ubuntu versions (like 5.4.x in Ubuntu 12.04)? 2 answers I purchased a new VPS from bluehost they provided me old version of PHP that's not supporting my website and It

  • Proper steps for updating Apache conf on production server?September 2

    I usually: Update my local near-replica ( ServerName directive and Logs will obviously be different ) of the production conf file and make my changes for things like rewrite rules. /etc/init.d/apache2 restart or graceful locally and ensure it's worki

  • Easy way to update apache on a server cluster with shared NFS conf?January 30

    we have a server setup where a server cluster connected with a db/files/conf server shared by nfs serve our sites, behind an Elastic Load Balancer at Amazon EC2. The setup works correctly, but keeping it up to date is becoming like hell, because the

  • Update Apache, PHP on Red Hat 7May 27

    I have an ancient server running Red Hat 7. I would like to update the httpd set up and obviously Red Hat does not provide updates for a system this old. What would be the best method to update these services on this machine? --------------Solutions-

  • Create/Update apache virtualhost on the same node for diff subdomains using Chef server?December 18

    I've two applications to deploy/run using chef on a single node under the same domain/subdomain. One is a Rails app and another is a Wordpress app. The Rails app will reside as the main app at say example.com and the wordpress at blog.example.com. An

  • Updating Apache 2.0.54 to 2.2.2 ?February 13

    I've done some googling, but till now I did not find a way to do an update/upgrade from Apache 2.0.54 to the new Apache 2.2.2 (exept this: http://httpd.apache.org/docs/2.2/install.html) Can it be done? Even when using ISPconfig?? --------------Soluti

  • Which repository do I add to automatically update Apache?

    Which repository do I add to automatically update Apache?May 21

    I guess the tittle says it all: I installed apache on my ubuntu(11.10), which repository do I add to automatically update it? --------------Solutions------------- Apache will automatically update to the latest available version for your distribution

  • How to update apache-utils 2.2 to 2.4 on ubuntu 12.04 LTS?July 11

    I started playing with ubuntu server edition. I'm still extremely new to ubuntu, but I can't seem to figure this problem out. I am running Ubuntu 12.04 LTS server. I need to use htpasswd to generate some password hashes, but bcrypt is supported only

  • ISPconfig : update Apache 2.2 to 2.4

    ISPconfig : update Apache 2.2 to 2.4July 7

    Hi all, I actually use ISPConfig (last version) on my Debian 7 with Apache 2.2. It work very fine But, I have to switch to Apache 2.4. Before I install it (from Testing Debian), what will I have to do before and after ? I saw that Apache 2.4 use new

  • Updated Apache from 2.2 to 2.4 and now my sub domains are brokenJuly 15

    Upon trying to visit any of my subdomains here is the error recieve in my error.log file: [Tue Jul 15 11:17:42.924790 2014] [core:alert] [pid 17309] [client 108.162.241.152:26427] /var/www/.htaccess: <IfModule not allowed here [Tue Jul 15 11:17:43.67

  • When will apt-get upgrade update Apache 2.4.7 to 2.4.12 July 8

    This question already has an answer here: Why don't the Ubuntu repositories have the latest versions of software? 7 answers Our PCI scan alerted us to vulnerabilities in Apache 2.4.7. while these affect modules we aren't even using, in order to pass

  • How to update Apache Ant version from 1.9.3 to 1.9.4September 15

    My O.S. version is Ubuntu 14.04 LTS. My Apache ant version is 1.9.3. ant -version Apache Ant(TM) version 1.9.3 compiled on April 8 2014 I want to update my Apache ant 1.9.4.(onwards) Please help me, because when I'm using sudo apt-get install ant to

  • How to update apache, mysql, phpmyadmin and php?November 14

    I have my own web server running on my raspberry pi, and all my programs are outdated. I would like to update my PHP, Apache, MySQL, and phpMyAdmin. Can anyone tell me how to update all of these;? ps, I m running a Debian distro called raspbian. Than

  • Updating apache/mysql/php solaris 11.2 with packagingDecember 8

    I'm attempting to update the web/amp install of a SPARC Solaris 11.2 install and I'm apparently missing something with the change from Solaris 10 -> 11. With pkg info -r amp, lists packages that are all out of date. Should I be looking at different r

Copyright (C) 2017 ceus-now.com, All Rights Reserved. webmaster#ceus-now.com 14 q. 0.498 s.