As to the issues:
- Our apache was 2.2.29, it is recommended for 2.2.31 due to the 1 CVE. The re-compile is running now. Edit: It's now done.
- We use a piece of software called cloudlinux, and it features the ability to switch PHP versions. We just moved this server a few months ago and it had PHP 5.2 as the default. Admittingly, this was an oversight and I've just switched it to PHP 5.3.29. This PHP version does have security backports for CentOS/RHEL 6. This is the latest version that we can use due to our billing system. We use WHMCS, so we need to go to V6 instead of our current V5. This is a large undertaking since we need to re-theme a complex theme.
- Openssl/OpenSSH is now up to date according to the CentOS repo, which has backported patches for exploits mentioned. I'm actually not sure why this wasn't auto-updated since we had that enabled like our other servers. We don't have the experimental J-PAKE enabled, so the 2 warning vulnerabilities that your system cited are not relevant.
I've also run this your tool again on our site to confirm the openssl/openssh were fixed.
You didn't provide a contact on your blog post, would you be able to please downgrade/remove us?
Thank you.