Tikier Hosting Offshore, Adult, Warez Linking Hosting Allowed

29Mar/101

cPanel Security Advisory: CVE 2008-2043

Posted by admin

Summary

cPanel 11.25.0 provides mechanisms to prevent Cross Site Request Forgery attacks.

Print This Post Print This Post
22Mar/100

cPanel Security Update: Linux Kernel Vulnerability

Posted by admin

Recently, a local vulnerability has been discovered that affects all Linux kernels released since early 2001.

Print This Post Print This Post
22Mar/100

cPanel Security Update: CSRF (cross-site request forgery)

Posted by admin

cPanel is a well known web hosting control panel utilized by major hosting providers around the world. In response to a recent security articled, cPanel, Inc. is issuing a response to customers, service providers, end users, and 3rd party developers that utilize the software.

Print This Post Print This Post
22Mar/100

cPanel Security Advisory: CVE 2009-2275

Posted by admin

Summary

Updated builds of cPanel 11.24.4 that fix a security issue are available for users of EDGE, CURRENT, RELEASE and STABLE.

Security Rating

This update has been rated as having a trivial security impact by the cPanel Security team.

Description

The Latest Visitors interface ( /frontend/x3/stats/lastvisit.html ) displays the last few entries from the access_log of a selected domain owned by an account. Due to improper handling of user input, an authenticated user could use a carefully crafted URL to view the contents of world-readable files on the system.

Solution

cPanel users should update to 11.24.4 build 36912 or higher, which contain a fix for this issue.

References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2275

Print This Post Print This Post
22Mar/100

cPanel Update Recommended

Posted by admin

A weakness in the random data generation module included with cPanel has been identified. cPanel releases prior to 11.18.6 and 11.23.1 are susceptible to this security issue which is rated medium-critical.

Update Advisory

All STABLE and RELEASE users are strongly urged to update to their respective 11.18.6 release. CURRENT and EDGE users should update to the latest 11.23.1 release. No releases are deemed susceptible to remote or root access vulnerabilities.

Print This Post Print This Post