Welcome, Guest. Please login or register.
Did you miss your activation email?
September 04, 2010, 04:16:50 am
Home Help Search Login Register

SysCP Forum  |  Announcements  |  English announcements  |  Topic: Security update: SysCP 1.4.2.2 released 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Print
Author Topic: Security update: SysCP 1.4.2.2 released  (Read 4980 times)
Flo
Administrator
*****
Offline Offline

Posts: 1230


WWW
« on: May 11, 2010, 09:37:33 pm »

Hello SysCP-Community,

today I received a mail about a severe security problem in the handling of open_basedir paths.
Customers are able to add whatever path they want via the documentroot of a domain by appending a colon to it and setting the open basedir path to use that domain documentroot, not the customer root.
SysCP 1.4.2.2 fixes this bug, together with a problem in safe_exec executing unwanted commands (#1288).
Every SysCP installation using the SysCP 1.4 series up to version 1.4.2.1 is affected by these security problems.
I want to thank Ian Banfield from brightlight.ch and massimo (in the bugtracker) for reporting these issues.

As always you'll find the updated downloads at files.syscp.org or http://www.syscp.org/download.html.
The direct link to the archive is http://files.syscp.org/releases/tgz/syscp-1.4.2.2.tar.gz.

If you don't want to update the whole package, consider using a patch.
Either you generate it directly from svn using the following command:
svn diff http://svn.syscp.org/tags/1.4.2.1 http://svn.syscp.org/tags/1.4.2.2
or download it at http://files.syscp.org/releases/diff/syscp-1.4.2.1-1.4.2.2.patch.
The most important part is the patch of functions.php.
Please make also sure you don't have any colons in any documentroot at the table panel_domains.

Regards, Flo
Logged
Pages: [1] Print 
SysCP Forum  |  Announcements  |  English announcements  |  Topic: Security update: SysCP 1.4.2.2 released « previous next »
Jump to:  


Login with username, password and session length

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 17 queries.