Description of problem: - Apache traffic server included in EPEL is v 5.3.0 (2015-06-22) - Included version has multiple associated known DoS vulnerabilities - CVE-2016-5396 - CVE-2017-5659 Version-Release number of selected component (if applicable): - Apache traffic server How reproducible: - Install Apache Traffic Server from EPEL Steps to Reproduce: 1. Add EPEL to repos and enable 2. yum -y install trafficserver 3. Actual results: - Installs v5.3.0 - http://mirror.overthewire.com.au/pub/epel/7/x86_64/t/trafficserver-5.3.0-1.el7.x86_64.rpm Expected results: - Installs v6.x.x release (eg. 6.2.2) Additional info:
Package has been retired [1] on epel7. [1] https://src.fedoraproject.org/rpms/trafficserver/c/99aa3258813f2fdd220c800acacf277949d29471?branch=epel7