Running CentOS release 5.7 (Final) and getting a fail for PCI due to CVE-2012-0053 (RHSA-2012:0128). I see this is patched into CentOS6. Any ideas about CentOS 5?
Thanks in advance!
Search found 7 matches
- 2012/03/02 19:51:45
- Forum: CentOS 5 - Security Support
- Topic: PCI 2.2.3-53.el5.centos.3
- Replies: 9
- Views: 4603
- 2011/08/07 05:38:27
- Forum: CentOS 5 - Security Support
- Topic: CentOS 5.6 and PCI Compliance
- Replies: 12
- Views: 8405
Re: CentOS 5.6 and PCI Compliance
Thanks Phil, what you say makes sense and it is going to cause ongoing pain. The main point of my original post was to see if other CentOS 5 users had some thoughts on addressing the problems I see. It sounds like CentOS 6 may help a reasonable amount as baseline version of apache is substantially n...
- 2011/08/06 20:45:40
- Forum: CentOS 5 - Security Support
- Topic: CentOS 5.6 and PCI Compliance
- Replies: 12
- Views: 8405
Re: CentOS 5.6 and PCI Compliance
A PCI scan must be completed by an ASV (Approved Scanning Vendor). From https://www.pcisecuritystandards.org: [quote]Whenever possible, ASVs must use two tools to categorize and rank vulnerabilities, and determine scan compliance: 1. The Common Vulnerability Scoring System (CVSS) version 2.0, which ...
- 2011/07/29 20:55:27
- Forum: CentOS 5 - Security Support
- Topic: CentOS 5.6 and PCI Compliance
- Replies: 12
- Views: 8405
Re: CentOS 5.6 and PCI Compliance
Right, I read those. My point is that while RedHat doesn't think CVE-2007-6203 is a vulnerability, our credit card processor's PCI scanner does and hence will not certify unless there is a compensating control. CVE-2008-0455/6 could be addressed by disabling mod_negotiation. CVE-2007-1741/3 could be...
- 2011/07/28 22:59:44
- Forum: CentOS 5 - Security Support
- Topic: CentOS 5.6 and PCI Compliance
- Replies: 12
- Views: 8405
CentOS 5.6 and PCI Compliance
I've been finding that there are a number of vulnerabilities appearing on PCI scans which RedHat has decided not to backport with respect to Apache httpd-2.2.3-45.el5.centos.1: e.g. CVE-2007-6203 CVE-2008-0455 CVE-2008-0456 CVE-2007-1741 CVE-2007-1743 Quite the hassle. I'm wondering if others have t...
- 2009/10/06 03:33:56
- Forum: CentOS 5 - Software Support
- Topic: Configuring Syslog-ng 3.0.3 with CentOS 5.3
- Replies: 2
- Views: 674
Re: Configuring Syslog-ng 3.0.3 with CentOS 5.3
UPDATE For some reason syslog-ng is essentially hardcoded to read in /opt/syslog-ng/etc/syslog-ng.conf. So part one of the problem was that it wasn't looking in /etc as per the syslog-ng doc. PS changing CONFFILE in the init script doesn't actually do anything. Problem two is that the structure of t...
- 2009/10/05 23:04:50
- Forum: CentOS 5 - Software Support
- Topic: Configuring Syslog-ng 3.0.3 with CentOS 5.3
- Replies: 2
- Views: 674
Configuring Syslog-ng 3.0.3 with CentOS 5.3
I installed syslog-ng-3.0.3-1.rhel5.i386.rpm and at first blush it appears to be working fine to /var/log/messages. However it doesn't seem to be doing any other ancillary logging as defined in syslog-ng.conf (I've had to mod /etc/init.d/syslog-ng to look in /etc). e.g. destination d_auth { file("/v...