On Wednesday 12 January 2005 23:49, Phil Beynon wrote:
> > > If you are not running any of the previosly mentioned PHP apps
> > > then it should be less of an issue. If you are then it's
> > > beneficial to upgrade. Pity these programs weren't written better
> > > before they were released really.
> > >
> > > Phil
> >
> > This list contains only apps that are highly critical to keep
> > without update. Be sure, it doesn't list a lot others which are
> > vulnerable too.
> >
> > We have released free update against this vulnerability a while
> > ago:
> >
> > Apache 1.3.33:
> > ( mod_ssl 2.8.22, mod_perl 1.29, mod_throttle 3.1.2, etc)
> > ftp://ftp.cobaltsupport.com/pub/csUPDATE/RaQ4/RaQ4-csUPDATE01-1.0.p
> >kg
> >
> > PHP 4.3.10:
> > ftp://ftp.cobaltsupport.com/pub/csUPDATE/RaQ4/RaQ4-PHP-4.3.10.pkg
> >
> > Installs fine on clean fully patched RaQ4. Should also install fine
> > on PkgMaster PHP 4.1.2 pkg. Not quite sure about others.
> >
> > You must install csUPDATE01 before csUPDATE02. RaQ4 apache has many
> > _locally exploitable_ security holes.
> >
> > WBR
> > Dmitry
> >
> > P.S.: (RaQ550 updates could be found here :
> > http://www.cobaltsupport.com/updates/raq550/ )
> > --
> > CobaltSupport.COM - Dynamic Support for your Cobalt Server
>
> I was thinking more along the lines that if a script kiddie is out
> looking for a popular application that they would be far more likely
> to find a site / server containing one of the ones mentioned and
> exploit it via this method than site where only custom scripting is
> employed such as I write & use.
>
> Dmitry,
> Is there a csUPDATE02 for the Raq4 as this didn't seem to be posted
> in the FTP directory above?

Will be posted shortly. Most critical, zlib update, is included into 
csUPDATE01 already. 

WBR
Dmitry
-- 
CobaltSupport.COM - Dynamic Support for your Cobalt Server


_______________________________________________
Cobaltfacts site list
[email protected]
http://list.cobaltfacts.com/mailman/listinfo.cgi/cobaltfacts

Reply via email to