The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

zlib security vulnerability ?

Discussion in 'Security' started by IRCBrasil, Nov 16, 2005.

  1. IRCBrasil

    IRCBrasil Well-Known Member

    Joined:
    Jul 22, 2004
    Messages:
    93
    Likes Received:
    0
    Trophy Points:
    6
    Hi, i was doing the cpanel update, when i saw this message:

    zlib version checking disabled. zlib versions <= 1.2.1 have a know security vulnerability
    See http://www.zlib.net/ for more information

    So, i did it:

    oot@matrix [/home/pousada/www]# rpm -qa |grep zlib
    zlib-1.1.4-8.1
    zlib-devel-1.1.4-8.1
    root@matrix [/home/pousada/www]#

    Well, if cpanel and/or up2date -u dont update zlib, can i do it by myself, or the cpanel must use the 1.1.4-8.1?

    Thanks people!
     
  2. PanelGuy

    PanelGuy Well-Known Member

    Joined:
    Oct 13, 2004
    Messages:
    106
    Likes Received:
    0
    Trophy Points:
    16
    ZLib and Fedora Core 4

    That's nice. They list Fedora Core 4 as effected, but only provide updates for Fedora core 3.
     
  3. abubin

    abubin Well-Known Member

    Joined:
    Dec 7, 2004
    Messages:
    393
    Likes Received:
    1
    Trophy Points:
    18
    that's strange, my fc4 is using zlib-1.2.2.2-5.fc4. Though that is not my cpanel machine, I update only using yum.

    But yes, it's better to comfirm with cpanel on version compatibility before doing manual upgrades.

    And my Cpanel RHEL3 is still running zlib-1.1.4-8.1.
     
    #3 abubin, Nov 16, 2005
    Last edited: Nov 16, 2005
  4. IRCBrasil

    IRCBrasil Well-Known Member

    Joined:
    Jul 22, 2004
    Messages:
    93
    Likes Received:
    0
    Trophy Points:
    6
    yeh... my box is RHEL3 too.. i think i will wait more before update zlib, maybe 1.2 dont work.
     
  5. PanelGuy

    PanelGuy Well-Known Member

    Joined:
    Oct 13, 2004
    Messages:
    106
    Likes Received:
    0
    Trophy Points:
    16
    According to the documentation, anything over 1.2.1 has the bug. So why is there a patch for Fedora 3 from Red Hat, but they ignore FC4, even thought they confirm the problem in FC4 too.
     
  6. chirpy

    chirpy Well-Known Member

    Joined:
    Jun 15, 2002
    Messages:
    13,475
    Likes Received:
    20
    Trophy Points:
    38
    Location:
    Go on, have a guess
    Remember a few things:

    1. RedHat backport security fixes into their code, so looking at the rpm version will give you no idea as to whether it's vulnerable or not, you would have to go through their errata pages.

    2. Fedora is a development OS is likely to have the latest version of most applications, as you exchanging stability for bleeding edge features. Fedora is also community supported, really, and isn't part of RedHat's support system anymore (though they use their resources and a lot of the developers work on Fedora too).
     
Loading...

Share This Page