Debian GNU/Linux 5.0 updated
The Debian project is pleased to announce the fourth update of its stable distribution Debian GNU/Linux 5.0 (codename "lenny"). This update mainly adds corrections for security problems to the stable release, along with a few adjustments for serious problems.
Please note that this update does not constitute a new version of Debian GNU/Linux 5.0 but only updates some of the packages included. There is no need to throw away 5.0 CDs or DVDs but only to update via an up-to-date Debian mirror after an installation, to cause any out of date packages to be updated.
Print This Post
cPanel Security Update: CSRF (cross-site request forgery)
cPanel is a well known web hosting control panel utilized by major hosting providers around the world. In response to a recent security articled, cPanel, Inc. is issuing a response to customers, service providers, end users, and 3rd party developers that utilize the software.
Print This Post
cPanel Security Advisory: CVE 2009-2275
Summary
Updated builds of cPanel 11.24.4 that fix a security issue are available for users of EDGE, CURRENT, RELEASE and STABLE.
Security Rating
This update has been rated as having a trivial security impact by the cPanel Security team.
Description
The Latest Visitors interface ( /frontend/x3/stats/lastvisit.html ) displays the last few entries from the access_log of a selected domain owned by an account. Due to improper handling of user input, an authenticated user could use a carefully crafted URL to view the contents of world-readable files on the system.
Solution
cPanel users should update to 11.24.4 build 36912 or higher, which contain a fix for this issue.
References
Print This Post
cPanel Update Recommended
A weakness in the random data generation module included with cPanel has been identified. cPanel releases prior to 11.18.6 and 11.23.1 are susceptible to this security issue which is rated medium-critical.
Update Advisory
All STABLE and RELEASE users are strongly urged to update to their respective 11.18.6 release. CURRENT and EDGE users should update to the latest 11.23.1 release. No releases are deemed susceptible to remote or root access vulnerabilities.
Print This Post
Prevent Your Site from Being Hacked
A Growth Industry
Recently the number of sites being hacked or infiltrated has risen rapidly. We see a lot of distraught site owners who have had their sites damaged, experienced a loss of rankings, or had data stolen.
Use Protection
Although most good hosting companies will protect their servers (and usually your site to some degree) it’s important to understand that you are responsible for your own site.
Print This Post
