DirectAdmin and CVE-2014-0224

Posted On // Leave a Comment

I currently have a new directadmin installation on debian 7.


I recently did some tuning including adding a GRE tunnel, and enabling HTTPS for the panel. Upon completion of HTTPS and GRE setup, I used the ssllabs test to check my SSL.


SSL Labs reports that I am vulnerable to CVE-2014-0224.


According to the debian security tracker and my installation, this is impossible.


Debian Security Tracker indicates that it was fixed in 1.0.1e-2+deb7u13/1.0.1e-2+deb7u14.


Dpkg reports 1.0.1e-2+deb7u14 is installed.


I don't get it.


http://ift.tt/1dvHQ0Z

0 comments:

Post a Comment