Resultados 1 a 3 de 3
  1. #1
    Super Moderador
    Data de Ingresso
    Sep 2010

    Alerta de Segurança cPanel & WHM 11.30

    Novo alerta de segurança da cPanel:

    Important: cPanel & WHM 11.30 Security Release

    cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system.

    cPanel has rated this update as having important security impact. Information on security ratings is available at SecurityLevels < AllDocumentation < TWiki.

    If your deployed cPanel & WHM servers are configured to automatically update when new releases are available, then no action is required. Your systems will update automatically. If you have disabled automatic updates, then you are highly encouraged to update your cPanel & WHM installs at your earliest convenience.


    Version of cPanel & WHM addresses all known vulnerabilities. The latest public releases of cPanel & WHM for all update tiers are published at Downloads - cPanel Inc..

    Security Issue Information

    The resolved security issues were identified by various members of the development and quality assurance teams at cPanel. There is no reason to believe that these vulnerabilities are known to the public. As such, cPanel will only release limited information regarding the vulnerabilities.

    Once sufficient time has passed to allow cPanel & WHM systems to automatically update their installed software to the new versions, cPanel will release additional information regarding the nature of the security issue. This Targeted Security Release addresses five vulnerabilities. Additional information is scheduled to be released December 6, 2012, via email.
    Siga-nos em nosso twitter: @wht_brasil

  2. #2
    Super Moderador
    Data de Ingresso
    Sep 2010
    mais problemas?

    Important: New Information about cPanel & WHM 11.30, 11.32, and 11.34 Updates Now Available


    cPanel & WHM;;, which fixes multiple security issues, is now available for download.

    cPanel has rated these updates as having important security impact. Information on security ratings is available at SecurityLevels < AllDocumentation < TWiki.


    The Perl Storable module provides support for serialization and deserialization of Perl data structures. In cPanel & WHM this functionality is used for caching data to disk and transferring data between processes. In many areas this caching and interprocess communication crosses privilege separation boundaries. A local malicious user could use this behavior to inject code into serialized data structures, thus allowing for code execution and possibility of privilege escalation.

    The Perl YAML::Syck module provides similar functionality as the Storable module. The version of YAML::Syck used in previous releases of cPanel & WHM allowed serialized data to be blessed into arbitrary packages as it was deserialized. This could be leveraged to perform unsafe actions in object destructors.

    The version of Locale::Maketext used in previous releases of cPanel & WHM suffered from two flaws in the _compile() function which allowed authenticated users to execute arbitrary code by supplying specially crafted translatable phrases.

    cPanel & WHM relies on the Crypt::Passwd::XS Perl module to perform password hashing. This module suffers from the same vulnerability disclosed in CVE-2012-2143 where passwords with the 0x80 character are truncated when hashed using the DES crypt algorithm. cPanel & WHM systems are configured by default to use the stronger MD5 and SHA512 crypt password hashing algorithms.

    The version of Cpanel::Locale used in previous releases of cPanel & WHM included two date formatting functions that passed unsanitized user input to a subprocess shell. An authenticated attacker could use this functionality to execute arbitrary shell commands on the local system bypassing normal restrictions on local code execution.

    These issues were discovered by various members of the Development and Quality Assurance teams at cPanel.


    We recommend updating your cPanel & WHM system as follows;

    Update cPanel & WHM 11.30 to or newer.
    Update cPanel & WHM 11.32 to or newer.
    Update cPanel & WHM 11.34 to or newer.

    To check which version of cPanel you have, go to What's my cPanel & WHM version number?

    A full listing of published versions can always be found at Downloads - cPanel Inc..


    Case 59926 | cPanel, Inc.
    Case 60203 | cPanel, Inc.
    Case 60970 | cPanel, Inc.
    Case 61251 | cPanel, Inc.
    Case 62230 | cPanel, Inc.
    Siga-nos em nosso twitter: @wht_brasil

  3. #3
    WHT-BR Top Member
    Data de Ingresso
    Nov 2010
    Rio de Janeiro - RJ
    Não aguento mais receber estes emails deles, por dia são mais de 10 emails!

Permissões de Postagem

  • Você não pode iniciar novos tópicos
  • Você não pode enviar respostas
  • Você não pode enviar anexos
  • Você não pode editar suas mensagens