> > If you are not running any of the previosly mentioned PHP apps then > > it should be less of an issue. If you are then it's beneficial to > > upgrade. Pity these programs weren't written better before they were > > released really. > > > > Phil > > > > This list contains only apps that are highly critical to keep without > update. Be sure, it doesn't list a lot others which are vulnerable too. > > We have released free update against this vulnerability a while ago: > > Apache 1.3.33: > ( mod_ssl 2.8.22, mod_perl 1.29, mod_throttle 3.1.2, etc) > ftp://ftp.cobaltsupport.com/pub/csUPDATE/RaQ4/RaQ4-csUPDATE01-1.0.pkg > > PHP 4.3.10: > ftp://ftp.cobaltsupport.com/pub/csUPDATE/RaQ4/RaQ4-PHP-4.3.10.pkg > > Installs fine on clean fully patched RaQ4. Should also install fine on > PkgMaster PHP 4.1.2 pkg. Not quite sure about others. > > You must install csUPDATE01 before csUPDATE02. RaQ4 apache has many > _locally exploitable_ security holes. > > WBR > Dmitry > > P.S.: (RaQ550 updates could be found here : > http://www.cobaltsupport.com/updates/raq550/ ) > -- > CobaltSupport.COM - Dynamic Support for your Cobalt Server
I was thinking more along the lines that if a script kiddie is out looking for a popular application that they would be far more likely to find a site / server containing one of the ones mentioned and exploit it via this method than site where only custom scripting is employed such as I write & use. Dmitry, Is there a csUPDATE02 for the Raq4 as this didn't seem to be posted in the FTP directory above? Regards, Phil ** http://www.diygear.com THE Online DIY Toolstore For DIY & Business ** Infolink Electronic Systems Ltd. http://www.infolinkelectronics.co.uk ** Professional Web Design & Cobalt Hosting Solutions ** Sun Cobalt iForce Reseller - Canon Silver Reseller ** Contact: [EMAIL PROTECTED] ** Tel / Fax 0121 458 4894 (office) 0121 441 3558 (home) _______________________________________________ Cobaltfacts site list [email protected] http://list.cobaltfacts.com/mailman/listinfo.cgi/cobaltfacts
