نمایش نتایج: از شماره 1 تا 1 , از مجموع 1

موضوع: مشکل امنیتی در سی پنل- به آخرین ورژن آپدیت کنید - Targeted Security Release 2012-05-31 Disclosure

  1. #1
    عضو دائم Woshka آواتار ها
    تاریخ عضویت
    Apr 2009
    نوشته ها
    1,456
    تشکر تشکر کرده 
    55
    تشکر تشکر شده 
    1,524
    تشکر شده در
    1,078 پست

    پیش فرض مشکل امنیتی در سی پنل- به آخرین ورژن آپدیت کنید - Targeted Security Release 2012-05-31 Disclosure

    The following disclosure covers the Targeted Security Release 2012-05-31. Each vulnerability is assigned an internal case number which is reflected below.

    Information regarding cPanel’s Security Level rankings can be found here:

    SecurityLevels < AllDocumentation < TWiki

    Case 59634

    Summary

    Arbitrary File Write vulnerability in Apache Piped Log Configuration

    Security Rating

    cPanel has assigned a Security Level of “Important” to this vulnerability. An important rating applies to vulnerabilities that allow system authentication levels to be compromised. These include allowing local users to elevate their privilege levels, unauthenticated remote users to see resources that should require authentication to view, the execution of arbitrary code by remote users, or any local or remote attack that could result in an denial of service.

    Description

    When using the Apache Piped Log Configuration, a sophisticated attacker could manually format log messages to take advantage of insufficient input validation in the splitlogs binary. When combined with a directory traversal attack, this vulnerability could allow the attacker to write to arbitrary files on the system.

    This vulnerability was discovered by the cPanel Quality Assurance Team. The Apache Piped Log Configuration is a feature which is disabled by default.

    Solution

    This issue is resolved in the following builds:

    11.32.3.19 and greater
    11.32.2.28 and greater
    11.30.6.8 and greater


    Please update your cPanel & WHM system to one of the aforementioned versions or the latest public release available. A full listing of published versions can always be found at Downloads - cPanel Inc..

    Additionally, this vulnerability is only present when the Apache Piped Log Configuration is in use.

    Downloads - cPanel Inc.

    Case 59656

    Summary

    Arbitrary Code Execution through cPDAVd

    Security Rating

    cPanel has assigned a Security Level of “Important” to this vulnerability. An important rating applies to vulnerabilities that allow system authentication levels to be compromised. These include allowing local users to elevate their privilege levels, unauthenticated remote users to see resources that should require authentication to view, the execution of arbitrary code by remote users, or any local or remote attack that could result in an denial of service.

    Description

    This is a vulnerability in the cPanel WebDAV implementation, cPDAVd. It would allow an authenticated user the ability to execute arbitrary code through improperly sanitized filenames.

    This vulnerability was discovered by the cPanel Quality Assurance Team.

    Solution

    This issue is resolved in the following builds:

    11.32.3.19 and greater
    11.32.2.28 and greater
    11.30.6.8 and greater


    Please update your cPanel & WHM system to one of the aforementioned versions or the latest public release available. A full listing of published versions can always be found at Downloads - cPanel Inc..
    فروش سرور مجازی
    http://www.maroonhost.net/vps-hosting.html
    مارون هاست
    برای خرید سرور تماس بگیرید 09123773197

  2. تعداد تشکر ها از Woshka به دلیل پست مفید


  3. # ADS




     

اطلاعات موضوع

کاربرانی که در حال مشاهده این موضوع هستند

در حال حاضر 1 کاربر در حال مشاهده این موضوع است. (0 کاربران و 1 مهمان ها)

موضوعات مشابه

  1. پاسخ ها: 0
    آخرين نوشته: August 25th, 2016, 20:06
  2. پاسخ ها: 0
    آخرين نوشته: November 15th, 2012, 02:00
  3. Norton Internet Security 2012 19.7.0.9 Final - بسته امنیتی نورتون
    توسط parsiaplus در انجمن مباحث دیگر
    پاسخ ها: 0
    آخرين نوشته: May 3rd, 2012, 10:18
  4. پاسخ ها: 0
    آخرين نوشته: August 13th, 2011, 10:21
  5. پاسخ ها: 0
    آخرين نوشته: March 8th, 2011, 19:44

مجوز های ارسال و ویرایش

  • شما نمیتوانید موضوع جدیدی ارسال کنید
  • شما امکان ارسال پاسخ را ندارید
  • شما نمیتوانید فایل پیوست کنید.
  • شما نمیتوانید پست های خود را ویرایش کنید
  •