Your HostICan Community  


Go Back   Your HostICan Community > HostICan Web Hosting > Virtual Private Servers (VPS)

Virtual Private Servers (VPS) Need help with your VPS plan on HostICan? Please feel free to ask and we'll give you the answers!

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 03-10-2008, 02:30 PM
itwasntme's Avatar
itwasntme itwasntme is offline
Senior Member
 
Join Date: Sep 2007
Posts: 142
Default Security Advisories From cPanel

Do you have automatic updates turned off in WHM so that you can handle updates manually and thus know when cPanel is updating?

I do, and I realized when I was updating cPanel today in response to a security advisory sent out by cPanel that there may be others with automatic updates off who don't know about the cPanel News Mailing List. It sends you notices about security issues and prompts you to update cPanel when necessary. If you're interested, you can sign up for the cPanel News Mailing List here.

Here's the most recent advisory regarding a vulnerability in Horde--the second this week--that came out via the News mailing list today as a sample of what you get:

Quote:
SECURITY ADVISORY: Official Horde Update to 3.1.7 and upgrades to
cPanel's PHP application security model

available in cPanel builds 11.18.3 and 11.19.3.

----------------------

Summary:
The Horde webmail application framework has been updated to 3.1.7.
Upgrades have
been made in cPanel's PHP application security model.

Description:
The Horde webmail application framework has been updated to 3.1.7 for
the official
fix to the previously announced arbitrary file inclusion
vulnerability. cPanel has
also made upgrades in cPanel's PHP application security model for Horde,
PHPMyAdmin, and PHPPGAdmin. These upgrades have been made to minimize
or mitigate
undiscovered vulnerabilities in these third-party applications while
running within
a cPanel installation.

Fix Details:
It is recommended that all cPanel servers running Horde be updated to
either
cPanel 11.18.3 or cPanel 11.19.3. If you do not wish to update
cPanel, it is
strongly recommended that you keep Horde disabled until these updates
have been
applied. You can disable horde on your cPanel system by unchecking
WHM ->
Server Configuration -> Tweak Settings -> Mail -> Horde Webmail, and
saving with
the new settings.

You can check your current version of cPanel by executing:
/usr/local/cpanel/cpanel -V

Updates can be run via the following command executed from a root shell:
/scripts/upcp

Updates can be run through WHM as well. Login to WHM, then select
cPanel -> Upgrade
to Latest Version -> Click to Upgrade.

References:
[announce] Horde 3.1.7 (final)

Credits:
cPanel would also like to thank Jeff Petersen and Rob Brown for the
additional
security information provided with regards to this update.
I hope it helps someone else, too.
Reply With Quote
  #2  
Old 03-10-2008, 02:34 PM
Shazam's Avatar
Shazam Shazam is offline
Forum Whip-Cracker
 
Join Date: Sep 2007
Location: Scottsdale, AZ
Posts: 1,036
Default

A cautionary note: You can choose which update branch to use, and I recommend at least RELEASE or STABLE; the latter if you want to be very, very careful.

CURRENT and lesser releases are essentially public betas, apt to have bugs and they can bring your site down. You don't want to deploy them for sites that you depend on to make a buck.
__________________
Best,
Shazam
HostICan Community Superhero
Reply With Quote
  #3  
Old 03-10-2008, 02:44 PM
itwasntme's Avatar
itwasntme itwasntme is offline
Senior Member
 
Join Date: Sep 2007
Posts: 142
Default

Thanks, Shazam. Yeah, I have been sticking with the RELEASE and so far, so good.
Reply With Quote
  #4  
Old 03-10-2008, 02:46 PM
Shazam's Avatar
Shazam Shazam is offline
Forum Whip-Cracker
 
Join Date: Sep 2007
Location: Scottsdale, AZ
Posts: 1,036
Default

Quote:
Originally Posted by itwasntme View Post
Thanks, Shazam. Yeah, I have been sticking with the RELEASE and so far, so good.
Yeah, when I tried CURRENT once because I wanted a newer MySQL version (now they're all in sync), I had frequent HTTP crashes and it all went away when I returned to RELEASE. Word to the wise. RELEASE is usually pretty good, though.
__________________
Best,
Shazam
HostICan Community Superhero
Reply With Quote
  #5  
Old 03-10-2008, 02:58 PM
roger's Avatar
roger roger is offline
Senior Member
 
Join Date: Sep 2007
Posts: 285
Default

I was told the only thing I should be doing to update is use SSH and /scripts/upcp
No reference to current, stable, etc.
Reply With Quote
  #6  
Old 03-10-2008, 03:28 PM
Shazam's Avatar
Shazam Shazam is offline
Forum Whip-Cracker
 
Join Date: Sep 2007
Location: Scottsdale, AZ
Posts: 1,036
Default

Quote:
Originally Posted by roger View Post
I was told the only thing I should be doing to update is use SSH and /scripts/upcp
No reference to current, stable, etc.
But that's not what the cPanel advisory says.
__________________
Best,
Shazam
HostICan Community Superhero
Reply With Quote
  #7  
Old 03-12-2008, 09:44 PM
lnxcode's Avatar
lnxcode lnxcode is offline
The British Kid
 
Join Date: Sep 2007
Location: Richmond, VA
Posts: 2,020
Send a message via AIM to lnxcode Send a message via Skype™ to lnxcode
Default

Yes, HostGator found this one... when about 100 people emailed them (according to what cPanel said)... so you do want to update as soon as possible to make sure you dont have this problem
__________________
Thanks,

Denis Motova
Affiliate / Operations Manager

HostICan Answers | Become a HostICan Affiliate | Create a Support Ticket.
Reply With Quote
Reply

Tags
advisories, cpanel, security

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
cPanel and WHM Log File Locations itwasntme Virtual Private Servers (VPS) 2 09-19-2008 01:29 PM
Accessing cPanel as VPS Owner BooYaKaSha Virtual Private Servers (VPS) 1 07-24-2008 10:39 PM
Add-On Domain's and cpanel. Burke Shared Hosting 3 06-29-2008 12:22 PM
Just Upgraded, FTP and cpanel login question... ScottHughes Virtual Private Servers (VPS) 4 01-16-2008 02:05 AM
Security TTTG The Lounge 2 11-30-2007 11:51 AM


All times are GMT -4. The time now is 01:41 AM.


Powered by vBulletin® Version 3.8.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.

Copyright © 2003 - 2008 HostICan. All Rights Reserved.