Re: Information about security

2020-11-04 Thread l0f4r0
Hi, 4 nov. 2020 à 19:15 de d...@randomstring.org: > steph b wrote: > >> or how to know which security patch >> >> are applied or missed for this package ? >> > zless "/usr/share/doc/apache2/changelog.Debian.gz" > > The changelog will include appropriate CVEs. > + https://security-tracker.debian.

Re: Information about security

2020-11-04 Thread Dan Ritter
steph b wrote: > I recently audit my company and see in the server response the http server > version (eg for debian buster : apache v2.4.38). > > 1st I know that : this response must not contain this information. ServerSignature Off ServerTokens Prod > 2nd When i search CVE about this version

Information about security

2020-11-04 Thread steph b
Hi, I'm a french student in security, and i have a question : I recently audit my company and see in the server response the http server version (eg for debian buster : apache v2.4.38). 1st I know that : this response must not contain this information. 2nd When i search CVE about this versio