Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Security A Security hole has been discovered in the cPanel's suexec/mod_php handlers.

Discussion in 'Security' started by Jedia, Jun 7, 2004.

  1. Jedia

    Jedia Well-Known Member

    Joined:
    Mar 18, 2004
    Messages:
    200
    Likes Received:
    0
    Trophy Points:
    166
    Location:
    CN
     
  2. techark

    techark Well-Known Member

    Joined:
    May 22, 2002
    Messages:
    280
    Likes Received:
    0
    Trophy Points:
    316
    Don't update yet it breaks cpanel they say updating ot C10 will fix it but I am at C12 and all cpanel webmail etc url's are broke,.
     
  3. Choppy

    Choppy Member

    Joined:
    May 8, 2002
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    301
    Are you sure its working i just finished upgrading.. But only allow it to upgrade to stable.

    And everything is still broken. /cpanel/ /webmail/ etc etc.

    Regards
    Phillip
     
  4. nickn

    nickn Well-Known Member
    PartnerNOC

    Joined:
    Jun 15, 2003
    Messages:
    619
    Likes Received:
    1
    Trophy Points:
    168
    Make sure you are running C12...still broke on C12?
     
  5. Choppy

    Choppy Member

    Joined:
    May 8, 2002
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    301
    snickn

    techark says he is running C12 but still the same.

    Regards
    Phillip
     
  6. techark

    techark Well-Known Member

    Joined:
    May 22, 2002
    Messages:
    280
    Likes Received:
    0
    Trophy Points:
    316
    Updating to Edge fixed it.
     
  7. Choppy

    Choppy Member

    Joined:
    May 8, 2002
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    301
    So breaking other things or risking other things is a better solution?

    Hmm.

    Regards
    Phillip
     
  8. techark

    techark Well-Known Member

    Joined:
    May 22, 2002
    Messages:
    280
    Likes Received:
    0
    Trophy Points:
    316
    Hey I am not a happy camper either this is 3 rd time in 4 days I have had to complie Apache across 60 something servers.

    Getting kind of old if you know what I mean.

    Firstit was update to 1.3.1 right away then a few hours after I did that it was ModSSL has to be done now this.
     
  9. bman

    bman Well-Known Member

    Joined:
    Dec 28, 2003
    Messages:
    119
    Likes Received:
    0
    Trophy Points:
    166
    but for some one running stable cpanel he/she should not upgrade apache ?
    and to upgrade justy run buildapache and click build with out changeing the options ?
     
    #9 bman, Jun 8, 2004
    Last edited: Jun 8, 2004
  10. Dreamer

    Dreamer Well-Known Member

    Joined:
    Jun 23, 2003
    Messages:
    129
    Likes Received:
    0
    Trophy Points:
    166
    Location:
    Bulgaria
    I'm on build 12 and /cpanel definetly works.
     
  11. techark

    techark Well-Known Member

    Joined:
    May 22, 2002
    Messages:
    280
    Likes Received:
    0
    Trophy Points:
    316
    The upgrade seems to have broken Front page on all our servers.

    ARCGHHHHHHH!!!!!
     
  12. bman

    bman Well-Known Member

    Joined:
    Dec 28, 2003
    Messages:
    119
    Likes Received:
    0
    Trophy Points:
    166
    i updated to WHM 9.4.0 cPanel 9.4.0-E13
    and did buildapache without changeing any options
    every thing seems working ok but did i need to change any options in buildapache ?
    or should i do /scripts/easyapache ?
    what option should i pick in /scripts/easyapache ? is it 5 or 1 ?
    thanks
     
  13. iko

    iko Well-Known Member
    PartnerNOC

    Joined:
    Jan 29, 2004
    Messages:
    56
    Likes Received:
    0
    Trophy Points:
    156
    I recommend not updating to a Current version. The STABLE tree is buggy enough to use buggier versions l
     
  14. kris1351

    kris1351 Well-Known Member

    Joined:
    Apr 18, 2003
    Messages:
    963
    Likes Received:
    0
    Trophy Points:
    166
    Location:
    Lewisville, Tx
    Seems we have less trouble running current versions than any other. We have been keeping all servers on Current since March with no issues.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  15. rodolfochka

    rodolfochka Active Member

    Joined:
    Feb 1, 2004
    Messages:
    35
    Likes Received:
    0
    Trophy Points:
    156
    Location:
    Mexico City
    I just updgraded Apache and cpanel to this:
    WHM 9.4.0 cPanel 9.4.0-C12

    and is working fine, the url's are working fine.
    There is no error in the main page:
    Security There are no known security problems with the build of cPanel you are using!


    rodolfochka
     
  16. chash

    chash Member

    Joined:
    Jan 11, 2003
    Messages:
    8
    Likes Received:
    0
    Trophy Points:
    151
    check again - new front page

    Since this morning (9.40 - C12)

    there's a new front page module

    Hope the /webmail redirect gets fixed quick
     
  17. pweb

    pweb Registered

    Joined:
    Feb 18, 2004
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    151
    Location:
    Tempe, AZ
    hmmm all this is confusing me.

    I did the upgrade few days ago, and all my PHP sites were down. I spent my Sunday fixing this.
    These are my current settings:
    WHM 9.2.0 cPanel 9.3.0-R5 and the Apache Core is the latest.

    Now I am still asked to update Apache, and Cpanel right after.

    Can somebody more experienced than me give some suggestions on what to do next?
    I am scared...

    tnx guys
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  18. iko

    iko Well-Known Member
    PartnerNOC

    Joined:
    Jan 29, 2004
    Messages:
    56
    Likes Received:
    0
    Trophy Points:
    156
    update apache using /scripts/easyapache or buildapache in WHM. You may be haven't updated the mod_ssl.
     
  19. pweb

    pweb Registered

    Joined:
    Feb 18, 2004
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    151
    Location:
    Tempe, AZ
    tnx iko.

    The first time I just clicked on the link provided in whm... that goes to scripts/buildapache

    brainless.... do u suggest I run the script from the shell instead?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  20. verdon

    verdon Well-Known Member

    Joined:
    Nov 1, 2003
    Messages:
    862
    Likes Received:
    3
    Trophy Points:
    168
    Location:
    Northern Ontario, Canada
    cPanel Access Level:
    Root Administrator
    I've had better luck from shell... a little more confusing at first, but it tends not to time out and stop like my browser does :)
     
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice