安全ID : NAS-201811-08
Security Advisory for Apache HTTP Server Vulnerability
发布日期 : November 8, 2018
通用漏洞披露 : N/A
受影响产品: QTS 4.2.6: build 20180531 and earlier versions
QTS 4.3.3: build 20180528 and earlier versions
QTS 4.3.4: build 20180528 and earlier versions
严重程度
低
状态
已解决
Summary
A reported Apache HTTP Server vulnerability may affect certain versions of QTS. If successfully exploited, the vulnerability could allow attackers to access sensitive information.
We have already fixed these issues in following versions.
- QTS 4.2.6: build 20180711 and later
- QTS 4.3.3: build 20180716 and later
- QTS 4.3.4: build 20180710 and later
Recommendation
To resolve the issue, we recommend updating QTS to the latest version.
If you are using the NAS as a web server, you must restore the default web server configuration after updating QTS. If you are using the NAS as a web server for virtual hosting, you must also enable the virtual host feature after restoring the default web server configuration.
Installing the QTS Update
- Log on to QTS as administrator.
- Go to Control Panel > System > Firmware Update.
- Under Live Update, click Check for Update.
QTS downloads and installs the latest available update.
Restoring the Default Web Server Configuration
- Log on to QTS as administrator.
- Go to Control Panel > Applications > Web Server.
- Under Maintenance, click Restore.
A confirmation message appears. - Click OK.
QTS restores the default configurations.
Enabling Virtual Hosting
- Log on to QTS as administrator.
- Go to Control Panel > Applications > Web Server > Virtual Host.
- Select Enable Virtual Host.
- Click Apply.
QTS applies the changes.
修订历史: V1.0 (November 8, 2018) - Published