We are happy to announce that cPanel, L.L.C. has released an update for EasyApache 4! This update includes a number of security updates for PHP versions 7.1.27, 7.2.16, and 7.3.3, as well as OpenSSL version 1.0.2r, and the addition of PassengerNodejs to passenger_apps.default. We are also adding ea-nodejs10 in preparation for work that will be released in cPanel & WHM Version 80. Please take a look at the release below, and then join us on Slack, Discord, or Reddit to talk about this update and much more.
2019-3-13
ea-apache2EA-8279: Remove noreplace from old EA3 config file in ea-apache24.spec ea-opensslEA-8265: Update OpenSSL to version 1.0.2r, drop 1.0.2q (with fix for
CVE-2019-1559)scl-php71scl-php71-metaEA-8267: Update PHP 7.1 to version 7.1.27, drop 7.1.26scl-php72scl-php72-metaEA-8271: Update PHP 7.2 to version 7.2.16, drop 7.2.15scl-php73scl-php73-metaEA-8275: Update PHP 7.3 to version 7.3.3, drop 7.3.2scl-ruby24-passengerEA-8238: Add PassengerNodejs to passenger_apps.defaultea-nodejs10EA-8125: Move ea-nodejs10 into production
This release also includes security patches that have been issued for CVEs (Common Vulnerabilities and Exposures), the details of which are included below.
SUMMARY
cPanel, L.L.C. has updated RPMs for EasyApache 4 with PHP versions 7.1.27, 7.2.16, and 7.3.3 and OpenSSL version 1.0.2r. This release addresses vulnerabilities related to CVE-2019-9637, CVE-2019-9641, CVE-2019-9640, CVE-2019-9638, CVE-2019-9639, CVE-2019-1559, and several other vulnerabilities which have not yet been assigned a number. We strongly encourage all PHP 7.1 users to upgrade to version 7.1.27, all PHP 7.2 users to upgrade to version 7.2.16, all PHP 7.3 users to upgrade to version 7.3.3 and all OpenSSL 1.0.2 users to upgrade to version 1.0.2r.
AFFECTED VERSIONS
All versions of PHP 7.1 through 7.1.26
All versions of PHP 7.2 through 7.2.15
All versions of PHP 7.3 through 7.3.2
All versions of OpenSSL 1.0.2 through 1.0.2q