Release Notification: 11.25.0 DNSONLY
Following the release of 11.25.0 STABLE, we are preparing to release an updated version of our DNSONLY builds for 11.25.0. This release offers extensive improvements to the scalability and overall performance of our DNSONLY product. Currently, the final release candidate is staged as DNSONLY-BETA and available for public testing and usage.
Print This Post
Technical Bulletin for cPanel 11.25.0
As you know, 11.25 has added a host of new features and functionality to cPanel & WHM. Tonight, 11.25 makes it to our STABLE builds. We will have additional technical staff on hand for the next few days to ensure the transition goes as smoothly as possible.
Print This Post
cPanel/WHM 11.25 EDGE Now Available
cPanel/WHM is published in four builds:
- EDGE - The latest build, with the newest features and least testing. We do not recommend running this build on a production web server.
- CURRENT - More mature and tested than EDGE.
- RELEASE - The preferred build for a production server, as it is generally current enough to contain the latest fixes and new features.
- STABLE - For conservative web hosts who do not wish to run the latest release.
Print This Post
cPanel Security Update: CSRF (cross-site request forgery)
cPanel is a well known web hosting control panel utilized by major hosting providers around the world. In response to a recent security articled, cPanel, Inc. is issuing a response to customers, service providers, end users, and 3rd party developers that utilize the software.
Print This Post
cPanel Security Advisory: CVE 2009-2275
Summary
Updated builds of cPanel 11.24.4 that fix a security issue are available for users of EDGE, CURRENT, RELEASE and STABLE.
Security Rating
This update has been rated as having a trivial security impact by the cPanel Security team.
Description
The Latest Visitors interface ( /frontend/x3/stats/lastvisit.html ) displays the last few entries from the access_log of a selected domain owned by an account. Due to improper handling of user input, an authenticated user could use a carefully crafted URL to view the contents of world-readable files on the system.
Solution
cPanel users should update to 11.24.4 build 36912 or higher, which contain a fix for this issue.
References
Print This Post
cPanel Update Recommended
A weakness in the random data generation module included with cPanel has been identified. cPanel releases prior to 11.18.6 and 11.23.1 are susceptible to this security issue which is rated medium-critical.
Update Advisory
All STABLE and RELEASE users are strongly urged to update to their respective 11.18.6 release. CURRENT and EDGE users should update to the latest 11.23.1 release. No releases are deemed susceptible to remote or root access vulnerabilities.
Print This Post
Direct cPanel VPS Licenses Now Available!
cPanel is now officially offering VPS-based licenses for direct purchase. If you have your own virtual private server, cloud computing service, or are located at a data center that is not a cPanel Partner, a Direct License allows you to download, install, and license cPanel directly. You can purchase Direct Licenses from cPanel on an annual basis.
Print This Post
Spam Assassin Ruleset Bug
The Quality Assurance team discovered a bug within the SpamAssassin ruleset that will mark messages sent in the year 2010 (that's today) and beyond with a higher spam score than expected. This bug can result in legitimate mail being flagged as spam.
Print This Post
cPanel 11.25 Tech Bulletin: updated bandwidth tracking requirements
cPanel 11.25 made a few feature improvements to the bandwidth tracking system built into WHM and cPanel. While these new features grants you a much more accurate and granular view of client bandwidth usage, customers with inadequately sized /var partitions may run into issues related to partition size and disk space consumption.
Print This Post
