Bitcoin Forum

Economy => Trading Discussion => Topic started by: Keyur @ Camp BX on March 04, 2012, 11:08:44 PM



Title: CampBX Security Bug Update
Post by: Keyur @ Camp BX on March 04, 2012, 11:08:44 PM
Hi all,
       The PCI security scan on CampBX identified a Linux/SSL-related vulnerability on our new server earlier this week.  This has caused us to lose the "PCI Compliant" status + logo temporarily.

After extensive testing our server administrators confirmed on Wednesday that this issue is a false positive.  The bug had been patched a long time ago but the version number was not updated, which caused the security scanner to throw a false positive.  Today McAfee's security team has verified and accepted our findings.  

It will take a couple of days to get the PCI certified status back, but we have been fully compliant and secure all along.

Thank you,
      Keyur



Title: Re: CampBX Security Bug Update
Post by: epetroel on March 04, 2012, 11:49:24 PM
Ha, nice.  Having this same issue right now with an e-comm site that I manage.  As you mentioned, seems red hat backports security fixes but doesn't change the version number.

Would think that with red hat being as popular as it is that McCaffee would handle this in their scanner, but no.