Section: Security

Update for cPanel & WHM Versions 11.38, 11.36, 11.34, & 11.32

cPanel, Inc. has published a security update for cPanel & WHM versions 11.38, 11.36, 11.34, and 11.32. This update resolves an issue with unchecked reseller privileges. We recommend all customers update to the latest build of each version as soon as possible. The cPanel Security Team has assigned a rating …

Posted in Security | Tagged:

cPanel & WHM Security Releases for 11.32, 11.34, and 11.36

cPanel has published security updates for all supported versions of cPanel & WHM. These updates contain fixes for a problem with the Roundcube webmail application. We recommend all customers update to the latest build of each version as soon as possible. The cPanel Security Team has assigned a rating of …

Posted in key, News, Security | Tagged: , , , ,

2013-02-26 cPanel & WHM Security Advisory for 11.32, 11.34, and 11.36

The following disclosure covers the Targeted Security Release 2013-02-26. Each vulnerability is assigned an internal case number which is reflected below. Information regarding cPanel’s Security Level rankings can be found here: http://go.cpanel.net/securitylevels Case 63700 Summary File disclosure and code execution using API 2 call Security Rating cPanel has assigned a …

Posted in key, Security | Tagged:

cPanel, Inc. Announces Additional Internal Security Enhancements

This is a follow up on the status of the security compromise that cPanel, Inc. experienced on Thursday, February 21, 2013. As mentioned in our email sent to cPanel Server Administrators who’ve opened a ticket with us in the past 6 months, on February 21 we discovered that one of …

Posted in Security

Important: cPanel & WHM 11.36, 11.34, and 11.32 Security Releases

cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated these updates as having important security impact. Information on …

Posted in News, Security | Tagged:

cPanel Security Team GNU Privacy Guard (GnuPG)

The cPanel Security Team uses a GNU Privacy Guard (GnuPG) key to secure communications. Mail sent to security@cpanel.net can be secured using our public key. GNuPG keys are also used to sign security advisories, and other public communications, issued by the cPanel Security Team. We expect to change the key …

Posted in key, Security | Tagged:

cPanel Security Release 11.34.1.7

cPanel has published a new security release, 11.34.1.7, containing Rails and ProFTPd security fixes. We recommend that all affected customers on the CURRENT, RELEASE, and STABLE tiers update to 11.34.1.7 as soon as possible. This release addresses two major vulnerabilities with Ruby on Rails (CVE-2012-5664 and CVE-2013-0156) which are resolved …

Posted in News, Release Announcements, Security | Tagged: ,

ModSecurity Changes

cPanel recently released EasyApache 3.16. This version of EasyApache contains an updated version of ModSecurity that has an important change to Rule IDs which will affect you. In addition to the RuleID change, another change in ModSecurity that affects directive names will be incorporated into EasyApache 3.18. Unique Rule IDs …

Posted in News, Security | Tagged: , ,

IMPORTANT: 11.30, 11.32, & 11.34 cPanel & WHM Updates Available

Important: New Information about cPanel & WHM 11.30, 11.32, and 11.34 Updates Now Available Summary: cPanel & WHM 11.30.7.4; 11.32.5.15; 11.34.0.11, which fixes multiple security issues, is now available for download. cPanel has rated these updates as having important security impact. Information on security ratings is available at http://go.cpanel.net/securitylevels. Description: …

Posted in News, Security | Tagged:

Case 62230

Case 62230 Summary Shell code injection via translatable phrases in Cpanel::Locale Security Rating cPanel has assigned a Security Level of “Important” to this vulnerability. Description The Cpanel::Locale module wraps around Perl’s Locale::Maketext module and extends it to provide additional Maketext tags and functionality. Locale::Maketext is used to render translatable phrases …

Posted in News, Security | Tagged:
Page 1 of 512345
Loading...