The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Cpanel security update to perl - LWP ssl problem

Discussion in 'Security' started by sloop, Apr 16, 2008.

  1. sloop

    sloop Well-Known Member
    PartnerNOC

    Joined:
    May 4, 2003
    Messages:
    68
    Likes Received:
    0
    Trophy Points:
    6
    Location:
    north carolina
    I have had two client's servers exhibit the same problem recently.

    Both servers were set to manual whm/cpanel updates, only automatic security updates.

    A change in perl modules sometime after April 10 broke some perl scripts that make HTTPS requests. One of them was making requests to ebay, the other to authorize.net.

    One of the servers had a clickcart pro shopping cart on it (perl) and was showing this error when trying to contact authorize.net via https:

    The other test perl script from ebay was showing

    The fix was to restore /usr/lib/perl5/site_perl from an earlier backup, or point the perl script to use an older perl interpreter installed on the system.

    Has anyone else seen this problem? It seems to be pretty significant but I haven't had any luck in tracking down the exact cause. I think this is the file in question that was updated causing the problem:

    /usr/lib/perl5/site_perl/5.8.8/LWP/Protocol/http.pm

    I tried manipulating LWP by manually setting $ENV{HTTPS_VERSION} to SSLv2 and then SSLv3 but that didnt help.
     
  2. sloop

    sloop Well-Known Member
    PartnerNOC

    Joined:
    May 4, 2003
    Messages:
    68
    Likes Received:
    0
    Trophy Points:
    6
    Location:
    north carolina
    for anyone else who stumbles upon this

    The problem was acknowledged in the libwww-perl package which includes LWP::Request

    Changelog: http://search.cpan.org/src/GAAS/libwww-perl-5.812/Changes

    For releast 5.812 that just came out today, they acknowledged and apparently fixed the problem:

     
  3. webstro

    webstro Member

    Joined:
    Mar 2, 2004
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    1
    Fix LWP SSL problem

    Thanks for the input. We have been struggling with this all afternoon. These are the steps that we took to upgrade to working version of LWP:

    # wget http://cpan.uwinnipeg.ca/cpan/authors/id/G/GA/GAAS/libwww-perl-5.812.tar.gz

    # tar xzf libwww-perl-5.812.tar.gz

    # cd libwww-perl-5.812

    # perl Makefile.PL

    // answer yes to all

    # make

    # make test

    # make install

    After that no more script failure.
     
Loading...

Share This Page