Page 1 of 1

Apache web server upgrade in Magicspam?

Posted: Tue Mar 07, 2023 11:16 am
by SantaPhil
Doing a recent security scan on our mail servers I noticed that the Apache web server used by Magicspam was version 2.4.9 which has some vulnerabilities.

I see that the latest version is 2.4.56

What is involved in updating the Apache web server in Magicspam so that we can pass our security tests? Would I just change out the httpd file or is it more involved?

Will you be coming out with an updated version of Magicspam for Mailenable soon containing an updated web server?

Thanks,

Phil

Re: Apache web server upgrade in Magicspam?

Posted: Tue Mar 07, 2023 1:28 pm
by magicspam
Hello Phil,

A new MagicSpam release will have to be prepared in order to upgrade to newer versions of Apache HTTP Server. You will in all likeliness not be able to configure this software in order to pass your security tests. However, we may be able to comment further if you provide us with more information on these security tests.

Otherwise, we have a MagicSpam for MailEnable release which includes Apache HTTP Server 2.4.51 version. If this version of Apache HTTP Server meets the requirements of your security tests, then we can provide you with further instructions on how to obtain it.

There is no other release which utilizes a newer version of the Apache HTTP Server than this one at the moment. We have created a development ticket to use a newer version of the Apache HTTP Server. This development ticket has been brought to the attention of our product team for further consideration.

Re: Apache web server upgrade in Magicspam?

Posted: Wed Mar 08, 2023 4:06 pm
by SantaPhil
Thank you for your quick response.

Yes the new version that you have would fix the scan problem. Although not the latest, the deficiency that the scanner caught would be fixed in the new version that you mentioned.

Please let me know where to obtain the new software. I am responsible for 2 Mailenable servers that are both running Magicspam, so I will install it on both once you get it to me.

Thanks again for your help with this.

Phil

Re: Apache web server upgrade in Magicspam?

Posted: Wed Mar 08, 2023 6:09 pm
by magicspam
Hey Phil,

It's no problem at all.

MagicSpam LITE for MailEnable 2.0.11-3 includes Apache HTTP Server 2.4.51 version. You can download and install the appropriate installer for your Windows system via:

MagicSpam LITE for MailEnable 2.0.11-3 (32-bit)
MagicSpam LITE for MailEnable 2.0.11-3 (64-bit)

We assume that you are using the LITE version, so let us know if that is not the case and require the installer for the PLUS version.

Thank you.