On Wednesday 12 January 2005 23:49, Phil Beynon wrote: > > > If you are not running any of the previosly mentioned PHP apps > > > then it should be less of an issue. If you are then it's > > > beneficial to upgrade. Pity these programs weren't written better > > > before they were released really. > > > > > > Phil > > > > This list contains only apps that are highly critical to keep > > without update. Be sure, it doesn't list a lot others which are > > vulnerable too. > > > > We have released free update against this vulnerability a while > > ago: > > > > Apache 1.3.33: > > ( mod_ssl 2.8.22, mod_perl 1.29, mod_throttle 3.1.2, etc) > > ftp://ftp.cobaltsupport.com/pub/csUPDATE/RaQ4/RaQ4-csUPDATE01-1.0.p > >kg > > > > PHP 4.3.10: > > ftp://ftp.cobaltsupport.com/pub/csUPDATE/RaQ4/RaQ4-PHP-4.3.10.pkg > > > > Installs fine on clean fully patched RaQ4. Should also install fine > > on PkgMaster PHP 4.1.2 pkg. Not quite sure about others. > > > > You must install csUPDATE01 before csUPDATE02. RaQ4 apache has many > > _locally exploitable_ security holes. > > > > WBR > > Dmitry > > > > P.S.: (RaQ550 updates could be found here : > > http://www.cobaltsupport.com/updates/raq550/ ) > > -- > > CobaltSupport.COM - Dynamic Support for your Cobalt Server > > I was thinking more along the lines that if a script kiddie is out > looking for a popular application that they would be far more likely > to find a site / server containing one of the ones mentioned and > exploit it via this method than site where only custom scripting is > employed such as I write & use. > > Dmitry, > Is there a csUPDATE02 for the Raq4 as this didn't seem to be posted > in the FTP directory above?
Will be posted shortly. Most critical, zlib update, is included into csUPDATE01 already. WBR Dmitry -- CobaltSupport.COM - Dynamic Support for your Cobalt Server _______________________________________________ Cobaltfacts site list [email protected] http://list.cobaltfacts.com/mailman/listinfo.cgi/cobaltfacts
