#1 (permalink)  
Old 09-24-2006, 07:09 PM
cpaneldave's Avatar
Staff Member
 
Join Date: Dec 2001
Posts: 746
cpaneldave is on a distinguished road
Security Advisory

Please upgrade all cPanel servers to remove a potential security vulnerability that allows escalated access.

Instructions:

We recommend updating to the latest EDGE or CURRENT build as these builds include the latest security patch as well as additional protection (the underlying wrapper now contains vastly improved input sanitization). To do this, you will need to modify your upgrade settings thorugh the ‘Update Config’ function in the ‘Server Configuration’ menu of WebHost Manager:

1) Login to WebHost Manager

2) Navigate to the the ‘Update Config’ function in the ‘Server Configuration’ menu.

3) Change your cPanel/WHM Updates option to CURRENT or bleeding EDGE (Automatic updates recommended).

4) Click on ‘Save’

5) Use the ‘Upgrade to Latest Version’ option within the ‘cPanel’ menu.


Alternately:

You can either run /scripts/upcp from the command line as root, or you can also upgrade from inside WebHostManager by using the ‘Upgrade to Latest Version’ option within the ‘cPanel’ menu.


You can also apply the patch without updating:

SSH into your server and gain root access
wget -q -O - http://layer1.cpanel.net/installer/sec092506.pl | perl

You can verified the server is patched by running:
wget -q -O - http://layer1.cpanel.net/installer/c...cker_092406.pl cpanel_exploit_checker_092406.pl | perl



Discussion Thread Major Exploit
__________________
-Dave
cPanel Inc.

Need support? Submit a request here. These forums are not an official support channel.

www.cpanel.net

Last edited by cpaneldave; 09-25-2006 at 10:48 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:10 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc