Case 60970 Summary Privilege escalation vulnerabilities due to the use of YAML::Syck for serialization Security Rating cPanel has assigned a Security Level of “Important” to this vulnerability. Description The Perl YAML::Syck module provides support for serialization and deserialization of data structures using the YAML format. In cPanel & WHM this …
Archive for December, 2012
Case 61251 Summary Arbitrary code execution via translatable phrases due to the use of Locale::Maketext Security Rating cPanel has assigned a Security Level of “Important” to this vulnerability. Description The Perl Locale::Maketext module is used to render translatable phrases into a user’s chosen locale. cPanel & WHM uses this module …
Ubuntu: 1653-1: Linux kernel (EC2) vulnerability
(Dec 4) The system could be made to run programs as an administrator.
(Dec 5) CUPS could be made to read files or run programs as an administrator.
Debian: 2582-1: xen: Multiple vulnerabilities
(Dec 7) Multiple denial of service vulnerabilities have been discovered in the xen hypervisor. One of the issue (CVE-2012-5513) could even lead to privilege escalation from guest to host. [More…]
Red Hat: 2012:1549-01: bind: Important Advisory
(Dec 6) Updated bind packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More…]
Red Hat: 2012:1551-01: mysql: Important Advisory
(Dec 7) Updated mysql packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More…]
Case 62230 Summary Shell code injection via translatable phrases in Cpanel::Locale Security Rating cPanel has assigned a Security Level of “Important” to this vulnerability. Description The Cpanel::Locale module wraps around Perl’s Locale::Maketext module and extends it to provide additional Maketext tags and functionality. Locale::Maketext is used to render translatable phrases …
IMPORTANT: 11.30, 11.32, & 11.34 cPanel & WHM Updates Available
Important: New Information about cPanel & WHM 11.30, 11.32, and 11.34 Updates Now Available Summary: cPanel & WHM 11.30.7.4; 11.32.5.15; 11.34.0.11, which fixes multiple security issues, is now available for download. cPanel has rated these updates as having important security impact. Information on security ratings is available at http://go.cpanel.net/securitylevels. Description: …
The following new functionality has been added:
[+] (Windows only) SmarterStats 7 support has been added.
The following bug has been fixed:
[-] (Windows only) open_basedir still operates after switching to ‘none’ (100496, 100497)
[-] If email has several recipients and one of them has full mailbox then email will not be delivered to anyone. Now the email is delivered to all recipients whose mailboxes quota is not exceeded, even if one of the recipients mailbox is full (92530)
(Dec 5) Programs that use LibTIFF could be made to crash or run programs if theyopened a specially crafted file.
(Dec 6) Bind could be made to crash if it received specially crafted networktraffic.
Debian: 2577-1: libssh: Multiple vulnerabilities
(Dec 1) Multiple vulnerabilities were discovered in libssh by Florian Weimer and Xi Wang: CVE-2012-4559: multiple double free() flaws [More…]
Debian: 2579-1: apache2: Multiple issues
(Nov 30) A vulnerability has been found in the Apache HTTPD Server: CVE-2012-4557 [More…]
IMPORTANT: 11.30 Security Release, cPanel & WHM
Important: cPanel & WHM 11.30 Security Release cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated this update …
IMPORTANT: 11.32 Security Release, cPanel & WHM
Important: cPanel & WHM 11.32 Security Release cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated this update …
Debian: 2580-1: libxml2: buffer overflow
(Dec 2) Jueri Aedla discovered a buffer overflow in the libxml XML library, which could result in the execution of arbitrary code. For the stable distribution (squeeze), this problem has been fixed in [More…]
Ubuntu: 1650-1: Linux kernel vulnerability
(Nov 30) The system could be made to crash under certain conditions.
Ubuntu: 1651-1: Linux kernel vulnerability
(Nov 30) The system could be made to crash under certain conditions.
Debian: 2581-1: mysql-5.1: Multiple vulnerabilities
(Dec 4) Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to a new upstream version, 5.1.66, which includes additional changes, such as performance improvements and corrections for data loss defects. These changes are described in the MySQL [More…]
Red Hat: 2012:1512-01: libxml2: Important Advisory
(Nov 29) Updated libxml2 packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having [More…]
IMPORTANT: 11.34 Security Release, cPanel & WHM
Important: cPanel & WHM 11.34 Security Release cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated this update …
Important Information about Today’s Update
Important information about today’s update for servers that updated between 1pm – 2pm CST Due to this morning’s security release, we are seeing heavier than normal network traffic, and have made adjustments that will compensate for this traffic. We apologize for excessive communication during this security release; we want every …
Ubuntu: 1652-1: Linux kernel (Oneiric backport) vulnerabilities
(Nov 30) Several security issues were fixed in the kernel.
(Dec 3) Regressions were introduced in the last Firefox update.
In the December 2012 survey we received responses from 633,706,564 sites – an increase of over 8 million since November. Microsoft IIS experienced the largest gain this month, with the movement of an advertising network of 4.7M Apache hostnames to IIS 7.5 contributing to an overall 8.2M increase – their largest in over a year. […]
Most Reliable Hosting Company Sites in November 2012
Rank
Company site
OS
Outage
hh:mm:ss
Failed
Req%
DNS
Connect
First
byte
Total 1
Datapipe
FreeBSD
0:00:00
0.007
0.094
0.018
0.037
0.056 2
Server Intellect
Windows Server 2008
0:00:00
0.010
0.012
0.064
0.142
0.337 3
Pair Networks
FreeBSD
0:00:00
0.014
0.254
0.083
0.169
0.507 4
XILO Communications Ltd.
Linux
0:00:00
0.017
0.419
0.067
0.552
0.697 5
ServInt
Linux
0:00:00
0.021
0.041
0.053
0.092
0.169 6
Kattare Internet Services
Linux
0:00:00
0.021
0.157
0.119
0.242
0.498 7
ServerStack
Linux
0:00:00
0.024
0.017
0.031
0.063
0.063 8
GoDaddy.com Inc
Windows Server 2008
0:00:00
0.028
0.447
0.119
0.888
1.461 9
INetU
Windows Server 2008
0:00:00
0.031
0.122
0.077
0.238
0.463 10
www.hostway.ro
Linux
0:00:00
0.031
0.306
0.140
0.917
1.560 See full table Unaffected by the aftermath of Hurricane Sandy’s landfall on the East Coast of the United States, Datapipe had the most reliable hosting company site in November. Webair, Logicworks, Serverstack, and INetU also had no outages in November despite their […]
The third release candidate for WordPress 3.5 is now available. We’ve made a number of changes over the last week since RC2 that we can’t wait to get into your hands. Hope you’re ready to do some testing! Final UI improvements for the new media manager, based on lots of great feedback. Show more information about […]
Joomla Community Magazine | December 2012
The December issue of the Joomla Community Magazine is here! Our stories this month:
Editors Introduction
On Track with Joomla!, by Alice Grevet
Feature Stories
My Joomla Timeline, by Helvecio
A Bright Future, by Alice Grevet
The X Factor and Women in Joomla!, by Dianne Henning
Sitebuilders
Comparison of Popular Display Article Modules, by Denys Nosov
Breaking Down Barriers for Joomla! Users, by Eden Orion
Part 2 – Review 9 Premium Web Hosting Services to take a Joomla! Site Live, by Tuan Bui
Project News
Leadership Highlights – December 2012, by Alice Grevet
Help the Joomla Certification Program Come Alive! – A Call for Volunteers, by Sarah Watz
Administrators
A New Way to Protect and Accelerate Your Site, by Ofer Cohen
Developers
Automating Your Component Demo Site, by David Hurley
Did you know…?
Trick to Use “Same” Email Address on Multiple Joomla User Accounts, by Nicholas G. Antimisiaris
Events
Kevinjohn Gallagher at the JWC12: Blunt, but Kilted., by Robbie Adair
JUG Bay Area, California, USA, by Jennifer Gress
The Joomla! Haikus
Post your Haikus for December, by Dianne Henning
Community Choice Extensions
The First Community Choice Extensions Winners! – December 2012, by Dianne Henning
International Stories
Browse the international articles submitted this month.
In our next issue
We want to publish your Joomla! story in the next JCM issue! So take a look at our Author Resources content to get a better idea of what we are looking for, and then register to become a JCM author and submit your Joomla! story!
The Oracle Media Centre – Press Releases – Sage Deutschland bindet MySQL von Oracle in Enterprise
MySQL bietet einfachere Verwaltung, höhere Leistung, plattformübergreifende Unterstützung und niedrigere Kosten