<<<>>> Trend Micro, Inc. April 17, 2014 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Trend Micro(TM) ServerProtect(TM) for Linux(TM) 3.0 Critical Patch - Build 1414 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Contents =================================================================== 1. Overview of this Critical Patch Release 1.1 Files Included in this Release 2. Documentation Set 3. System Requirements 4. Installation/Uninstallation 4.1 Installation 4.2 Uninstallation 5. Post-installation Configuration 6. Known Issues 7. Release History 8. Contact Information 9. About Trend Micro 10. License Agreement =================================================================== 1. Overview of this Critical Patch Release ====================================================================== This critical patch resolves the following issue: Issue: Both the Apache(TM) and OpenSSL modules in ServerProtect for Linux 3.0 are out-of-date and OpenSSL 1.0.1e is affected by a vulnerability. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: This critical patch upgrades the Apache module to version 2.2.27 and the OpenSSL module to version 1.0.1g. 1.1 Files Included in this Release =================================================================== A. Files for Current Issue ------------------------------------------------------------------- Files for Issue ------------------------------------------------------------------- Filename Build No. ------------------------------------------------------------------- splxhttpd 3.0.1414 libapr-1.so.0.5.0 3.0.1414 libaprutil-1.so.0.5.3 3.0.1414 cp_deploy_script.sh n/a B. Files for Previous Issues ------------------------------------------------------------------- Not applicable. 2. Documentation Set ====================================================================== In addition to this readme.txt, the documentation set for this product includes the following: o Getting Started Guide -- product overview, installation planning, installation steps and basic information intended to help you deploy ServerProtect for Linux smoothly. o Administration Guide -- Provides post-installation instructions on how to configure the settings to help you get ServerProtect for Linux "up and running". Also includes instructions on performing other administrative tasks for the day-to-day maintenance of ServerProtect for Linux. o Readme.txt files -- version enhancements, basic installation, known issues, and release history. o Electronic versions of the printed manuals are available at: http://docs.trendmicro.com/ o Online help -- Context-sensitive help screens that provide guidance for performing a task. o TrendEdge is a program for Trend Micro employees, partners, and other interested parties that provides information on unsupported, innovative techniques, tools, and best practices for Trend Micro products. The TrendEdge database contains numerous documents covering a wide range of topics. http://trendedge.trendmicro.com o Knowledge Base -- a searchable database of known product issues, including specific problem-solving and troubleshooting topics. http://esupport.trendmicro.com 3. System Requirements ====================================================================== Install this critical patch only on computers protected by ServerProtect for Linux 3.0 Patch 5 for Service Pack 1. 4. Installation/Uninstallation ====================================================================== 4.1 Installation =================================================================== To install this critical patch: 1. Log on as a root user. 2. Upload and copy the critical patch file to a working directory. For example, "/home/workdir." 3. Type the following command to extract the critical patch files from the "tar.gz" file. # tar zxvf splx_30_lx_en_criticalpatch1414.tar.gz 4. Execute the following command: #./cp_deploy_script.sh The following original files: - "/opt/TrendMicro/SProtectLinux/SPLX.httpd/bin/splxhttpd" - "/opt/TrendMicro/SProtectLinux/SPLX.httpd/lib/ libapr-1.so.0.4.8" - "/opt/TrendMicro/SProtectLinux/SPLX.httpd/lib/ libaprutil-1.so.0.5.2" are backed-up as: - "/opt/TrendMicro/SProtectLinux/SPLX.httpd/bin/ splxhttpd.bak.cp1414" - "/opt/TrendMicro/SProtectLinux/SPLX.httpd/lib/ libapr-1.so.0.4.8.bak.cp1414" - "/opt/TrendMicro/SProtectLinux/SPLX.httpd/lib/ libaprutil-1.so.0.5.2.bak.cp1414" 4.2 Uninstallation =================================================================== To roll back to the previous build: 1. Log on as a root user. 2. Stop ServerProtect for Linux using the following command: # /etc/init.d/splx stop 3. Rename the backup file created during installation by running the following commands: # cd /opt/TrendMicro/SProtectLinux/SPLX.httpd/bin/ # cp /opt/TrendMicro/SProtectLinux/SPLX.httpd/bin/ splxhttpd.bak.cp1414 splxhttpd # cd /opt/TrendMicro/SProtectLinux/SPLX.httpd/lib/ # cp /opt/TrendMicro/SProtectLinux/SPLX.httpd/lib/ libapr-1.so.0.4.8.bak.cp1414 libapr-1.so.0.4.8 # cp /opt/TrendMicro/SProtectLinux/SPLX.httpd/lib/ libaprutil-1.so.0.5.2.bak.cp1414 libaprutil-1.so.0.5.2 # rm libapr-1.so.0 # rm libaprutil-1.so.0 # rm libapr-1.so.0.5.0 # rm libaprutil-1.so.0.5.3 # ln -s /opt/TrendMicro/SProtectLinux/SPLX.httpd/lib/ libapr-1.so.0.4.8 /opt/TrendMicro/SProtectLinux/SPLX.httpd/ lib/libapr-1.so.0 # ln -s /opt/TrendMicro/SProtectLinux/SPLX.httpd/lib/ libaprutil-1.so.0.5.2 /opt/TrendMicro/SProtectLinux/ SPLX.httpd/lib/libaprutil-1.so.0 4. Start ServerProtect for Linux by running the following command: # /etc/init.d/splx start 5. Post-installation Configuration ====================================================================== No post-installation steps are required. Note: Trend Micro recommends that you update your scan engine and virus pattern files immediately after installing this critical patch. 6. Known Issues ====================================================================== There are no known issues for this critical patch release. 7. Release History ====================================================================== See the following web site for more information about updates to this product: http://downloadcenter.trendmicro.com 8. Contact Information ====================================================================== A license to the Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, Maintenance must be renewed on an annual basis at Trend Micro's then-current Maintenance fees. You can contact Trend Micro via fax, phone, and email, or visit us at: http://www.trendmicro.com Evaluation copies of Trend Micro products can be downloaded from our web site. Global Mailing Address/Telephone numbers ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ For global contact information in the Asia/Pacific region, Australia and New Zealand, Europe, Latin America, and Canada, refer to: http://www.trendmicro.com/en/about/overview.htm The Trend Micro "About Us" screen displays. Click the appropriate link in the "Contact Us" section of the screen. Note: This information is subject to change without notice. 9. About Trend Micro ====================================================================== Trend Micro Incorporated, a global leader in Internet content security and threat management, aims to create a world safe for the exchange of digital information for businesses and consumers. A pioneer in server-based antivirus with over 20 years experience, we deliver top-ranked security that fits our customers’ needs, stops new threats faster, and protects data in physical, virtualized and cloud environments. Powered by the Trend Micro Smart Protection Network(TM) infrastructure, our industry-leading cloud-computing security technology and products stop threats where they emerge, on the Internet, and are supported by 1,000+ threat intelligence experts around the globe. For additional information, visit www.trendmicro.com. Copyright 2014, Trend Micro Incorporated. All rights reserved. Trend Micro, the t-ball logo, Smart Protection Network, and ServerProtect are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other marks are the trademarks or registered trademarks of their respective companies. 10. License Agreement ====================================================================== Information about your license agreement with Trend Micro can be viewed at: http://us.trendmicro.com/us/about/company/user_license_agreements/ Third-party licensing agreements can be viewed: - By selecting the "About" option in the application user interface - By referring to the "Legal" page of the Getting Started Guide or Administrator's Guide