Section: Security

TSR Update

The following disclosure covers the Targeted Security Release 2013-06-05. Each vulnerability is assigned an internal case number which is reflected below. Information regarding the cPanel Security Level rankings can be found here: http://go.cpanel.net/securitylevels Case 68189 Summary An arbitrary files read and unlink vulnerability in cPanel, WHM, and Webmail. Security Rating …

Posted in Security | Tagged: ,

Important: 2013-06-05 Targeted Security Releases

cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated these updates as having important security impact. Information on …

Posted in Security | Tagged: ,

IMPORTANT: cPanel Security Notice 2013-06-03

SUMMARY The Apache mod_rewrite module fails to sanitize input, which may lead to arbitrary command execution in some circumstances. SECURITY RATING The cPanel Security Team has rated this update has having critical security impact. Information on security ratings is available at: http://go.cpanel.net/securitylevels. You are strongly encouraged to run EasyApache and …

Posted in Security | Tagged:

Update for cPanel & WHM Versions 11.38, 11.36, 11.34, & 11.32

cPanel, Inc. has published a security update for cPanel & WHM versions 11.38, 11.36, 11.34, and 11.32. This update resolves an issue with unchecked reseller privileges. We recommend all customers update to the latest build of each version as soon as possible. The cPanel Security Team has assigned a rating …

Posted in Security | Tagged:

cPanel & WHM Security Releases for 11.32, 11.34, and 11.36

cPanel has published security updates for all supported versions of cPanel & WHM. These updates contain fixes for a problem with the Roundcube webmail application. We recommend all customers update to the latest build of each version as soon as possible. The cPanel Security Team has assigned a rating of …

Posted in key, News, Security | Tagged: , , , ,

2013-02-26 cPanel & WHM Security Advisory for 11.32, 11.34, and 11.36

The following disclosure covers the Targeted Security Release 2013-02-26. Each vulnerability is assigned an internal case number which is reflected below. Information regarding cPanel’s Security Level rankings can be found here: http://go.cpanel.net/securitylevels Case 63700 Summary File disclosure and code execution using API 2 call Security Rating cPanel has assigned a …

Posted in key, Security | Tagged:

cPanel, Inc. Announces Additional Internal Security Enhancements

This is a follow up on the status of the security compromise that cPanel, Inc. experienced on Thursday, February 21, 2013. As mentioned in our email sent to cPanel Server Administrators who’ve opened a ticket with us in the past 6 months, on February 21 we discovered that one of …

Posted in Security

Important: cPanel & WHM 11.36, 11.34, and 11.32 Security Releases

cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated these updates as having important security impact. Information on …

Posted in News, Security | Tagged:

cPanel Security Team GNU Privacy Guard (GnuPG)

The cPanel Security Team uses a GNU Privacy Guard (GnuPG) key to secure communications. Mail sent to security@cpanel.net can be secured using our public key. GNuPG keys are also used to sign security advisories, and other public communications, issued by the cPanel Security Team. We expect to change the key …

Posted in key, Security | Tagged:

cPanel Security Release 11.34.1.7

cPanel has published a new security release, 11.34.1.7, containing Rails and ProFTPd security fixes. We recommend that all affected customers on the CURRENT, RELEASE, and STABLE tiers update to 11.34.1.7 as soon as possible. This release addresses two major vulnerabilities with Ruby on Rails (CVE-2012-5664 and CVE-2013-0156) which are resolved …

Posted in News, Release Announcements, Security | Tagged: ,
Page 1 of 512345
Loading...