The annual cPanel Conference is headed home to vibrant Houston, TX! Attracting attendees from around the globe, you will get an exclusive opportunity for personal development, intense learning, and the best networking events in the industry. While we believe that there are countless reasons why you should attend the cPanel Annual Conference, we’ve managed to narrow it down to five. Hear from the experts Our speakers are …
Archive for July, 2018
We gathered the top news stories of July from the world of web hosting news to help give you a glance at what’s going on in the industry right now.
The post Web Hosting News Roundup for July: What’s the latest? appeared first on Plesk.
Joomla 3.8.11 Release

Joomla 3.8.11 is now available. This is a bug fix release for the 3.x series of Joomla including over 35 bug fixes and improvements.
(Jul 30) New version 2.6.2. Security fix for CVE-2018-14339, CVE-2018-14340, CVE-2018-14341, CVE-2018-14342, CVE-2018-14343, CVE-2018-14344, CVE-2018-14367, CVE-2018-14368, CVE-2018-14369, CVE-2018-14370.
(Jul 27) upstream security fix release
(Jul 30) Several security issues were fixed in MySQL.
(Jul 30) An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
(Jul 30) An update for memcached is now available for Red Hat OpenStack Platform 10.0 (Newton) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
(Jul 27) upstream security fix release
(Jul 29) Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file.
(Jul 29) Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.
(Jul 29) Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file.
(Jul 29) Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA
(Jul 26) An update for procps is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact
(Jul 26) An update for ceph is now available for Red Hat Ceph Storage 2.5 for Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
(Jul 28) Jann Horn discovered that FUSE, a Filesystem in USErspace, allows the bypass of the ‘user_allow_other’ restriction when SELinux is active (including in permissive mode). A local user can take advantage of this flaw in the fusermount utility to bypass the system configuration and
(Jul 27) Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA
(Jul 26) A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
(Jul 26) A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
(Jul 27) Fixes **CVE-2017-11332**, **CVE-2017-11358**, and **CVE-2017-11359**. —- **Prevents division by zero in `src/ao.c`** This bug is hard to reproduce, depending on the HW configuration or installed OS parts. For me, it can be reproduced only in `mock`. In this update, error message should be displayed instead of SIGFPE.
(Jul 26) Update to 1.2.6 to fix a local authenticated privilege escalation bug (CVE-2018-10900). The issue has been discovered and responsibly disclosed by Denis Andzakovic: https://pulsesecurity.co.nz/advisories/NM-VPNC-Privesc
(Jul 26) USN-3722-1 introduced a regression in ClamAV.
(Jul 26) A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
(Jul 26) An update for ceph is now available for Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
(Jul 27) Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-4117
The Legacy Backup system will be deprecated in cPanel & WHM Version 74, and we anticipate support for Legacy Backups will be removed in Version 82 (currently expected in mid-2019). Before that happens, though, we are focusing on expanding the functionality available for the “new” Backup System. This replacement to the Legacy Backup system offers a more robust, faster, and over-all better backup solution. Better, Stronger… In case you haven’t heard, the cPanel & WHM Backup System, …
(Jul 25) This update includes the latest upstream release, **httpd 2.4.34**, with multiple bug fixes and enhancements. See http://www.apache.org/dist/httpd/CHANGES_2.4.34 for more information on the changes in this version. A security vulnerability is addressed in this update: * `mod_md`: DoS via Coredumps on specially crafted requests (CVE-2018-8011)
(Jul 25) New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801
(Jul 23) Several security issues were fixed in Mutt.
(Jul 25) ClamAV could be made to hang if it opened a specially crafted file.