Why there are no updated packages for CVE-2014-8109
Issue
- PCI compliance audit is failing because the most current version of
httpd
for RHEL7 available seems to be 2.4.6. The audit calls for 2.4.11 and for the remediation of CVE-2014-8109, which Red Hat has markedWONTFIX
as per BUG 1174077. If I can upgrade to 2.4.11 this system will pass PCI audit.
Environment
- Red Hat Enterprise Linux 7
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.