> > If you are not running any of the previosly mentioned PHP apps then
> > it should be less of an issue. If you are then it's beneficial to
> > upgrade. Pity these programs weren't written better before they were
> > released really.
> >
> > Phil
> >
>
> This list contains only apps that are highly critical to keep without
> update. Be sure, it doesn't list a lot others which are vulnerable too.
>
> We have released free update against this vulnerability a while ago:
>
> Apache 1.3.33:
> ( mod_ssl 2.8.22, mod_perl 1.29, mod_throttle 3.1.2, etc)
> ftp://ftp.cobaltsupport.com/pub/csUPDATE/RaQ4/RaQ4-csUPDATE01-1.0.pkg
>
> PHP 4.3.10:
> ftp://ftp.cobaltsupport.com/pub/csUPDATE/RaQ4/RaQ4-PHP-4.3.10.pkg
>
> Installs fine on clean fully patched RaQ4. Should also install fine on
> PkgMaster PHP 4.1.2 pkg. Not quite sure about others.
>
> You must install csUPDATE01 before csUPDATE02. RaQ4 apache has many
> _locally exploitable_ security holes.
>
> WBR
> Dmitry
>
> P.S.: (RaQ550 updates could be found here :
> http://www.cobaltsupport.com/updates/raq550/ )
> --
> CobaltSupport.COM - Dynamic Support for your Cobalt Server

I was thinking more along the lines that if a script kiddie is out looking
for a popular application that they would be far more likely to find a site
/ server containing one of the ones mentioned and exploit it via this method
than site where only custom scripting is employed such as I write & use.

Dmitry,
Is there a csUPDATE02 for the Raq4 as this didn't seem to be posted in the
FTP directory above?

Regards,

Phil

** http://www.diygear.com THE Online DIY Toolstore For DIY & Business
** Infolink Electronic Systems Ltd. http://www.infolinkelectronics.co.uk
** Professional Web Design & Cobalt Hosting Solutions
** Sun Cobalt iForce Reseller - Canon Silver Reseller
** Contact: [EMAIL PROTECTED]
** Tel / Fax 0121 458 4894 (office) 0121 441 3558 (home)


_______________________________________________
Cobaltfacts site list
[email protected]
http://list.cobaltfacts.com/mailman/listinfo.cgi/cobaltfacts

Reply via email to