The People of WordPress feature this month shares the story of web and plugin developer Juanfra Aldasoro from Argentina.
Archive for March, 2022
Ubuntu 5358-2: Linux kernel vulnerabilities
Several security issues were fixed in the Linux kernel.
Ubuntu 5357-2: Linux kernel vulnerability
The system could be made to crash or run programs as an administrator.
Welcome to the cPanel & WHM® contribution to the ELevate project by the AlmaLinux OS Foundation. ELevate enables upgrades between major versions of RedHat® Enterprise Linux® (RHEL) derivatives. At cPanel, we’ve created the cPanel ELevate tool that manages the ELevate process end-to-end so that systems administrators can safely and efficiently upgrade a cPanel & WHM server. Why ELevate Your cPanel & WHM Server? Sysadmins struggle when it’s time to do operating system upgrades. They’re very costly …
The post ELevating cPanel & WHM first appeared on cPanel Blog.
Ubuntu 5362-1: Linux kernel (Intel IOTG) vulnerabilities
Several security issues were fixed in the Linux kernel.
Ubuntu 5361-1: Linux kernel vulnerabilities
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in Tomcat.
rsync could be made to crash or run programs if it received specially crafted network traffic.
Several security issues were fixed in DOSBox.
Ubuntu 5358-1: Linux kernel vulnerabilities
Several security issues were fixed in the Linux kernel.
Ubuntu 5357-1: Linux kernel vulnerability
The system could be made to crash or run programs as an administrator.
Fix for CVE-2022-0860
Fix for CVE-2022-0860
Fix CVE-2022-1122.
Fedora 35: mingw-openjpeg2 2022-9515529c96
Fix CVE-2022-1122.
# UnrealIRCd 6.0.2 UnrealIRCd 6.0.2 comes with several nice feature enhancements along with some fixes. It also includes a fix for a crash bug that can be triggered by ordinary users. ## Fixes * Fix crash that can be triggered by regular users if you have any `deny dcc` blocks in the config or any spamfilters with the `d` (DCC) target. * Fix infinite hang on “Loading
The 5.16.18 stable kernel update contains a number of important fixes across the tree.
How to Write Your First 360 Monitoring Plugin
As a product manager at Plesk, I am always interested in how our products work to gain an in-depth understanding of the tools we’re handing out to our customers. That’s why after the release of 360 Monitoring, I used the tool to build customized dashboards with full server and site monitoring including all pertinent information available by default on the platform. However, I realized I was missing something: as a user of the Plesk WP Toolkit, I’m accustomed to enjoying an overview of all my WordPress Websites and what their status is according to the Toolkit. So I decided to…
The post How to Write Your First 360 Monitoring Plugin appeared first on Plesk.
Chromium could be made to execute arbitrary code if it received a specially crafted input.
Last week, we finally saw the long-awaited return of CloudFest to its original and physical form at the wonderful Europa Park in Germany. In between the rollercoasters left and right, it was a thrilling ride to be able to go from booth to booth in person again. At last, the Plesk team was firmly back in place, connecting both people and ideas to create new business opportunities that matter. With the intention to meet, greet and share a beer between our teeth, it was an absolute pleasure to be back together with our partners and attendees at CloudFest 2022. Now…
The post Plesk at CloudFest 2022 appeared first on Plesk.
RedHat: RHSA-2022-1102:01 Important: httpd:2.4 security update
An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2022-1103:01 Important: kpatch-patch security update
An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
RedHat: RHSA-2022-1106:01 Important: kernel security update
An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2022-1107:01 Important: kernel security update
An update for kernel is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat Enterprise Linux 7.6 Telco Extended Update Support, and Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions.
RedHat: RHSA-2022-1112:01 Important: openssl security update
An update for openssl is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2022-1108:01 Moderate: Red Hat Process Automation Manager
An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2022-1104:01 Important: kernel security update
An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2022-1110:01 Moderate: Red Hat Decision Manager 7.12.1
An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
USN-5313-1 introduced a regression in OpenJDK 11.
In the March 2022 survey we received responses from 1,169,621,187 sites across 272,177,331 unique domains and 11,877,217 web-facing computers. This reflects a loss of 4.00 million sites, but a gain of 977,000 domains and 103,000 web facing computers.
Cloudflare gained the largest number of sites, with 1.32 million more than in the February survey. Its growth was also consistent across other metrics, having gained +176,000 domains (+0.77%) and +256,000 active sites (+1.24%), with an extra 0.12pp share of the top one million sites.
nginx, the current leader by most metrics, had a particularly strong growth in terms of domains, having gained 978,000 domains (+1.35%) this month—the largest gain of any vendor in this metric. Though it lost 2.98 million sites, it appears to be serving more interesting content overall, as measured by a 158,000 increase in its number active sites. It also gained the most additional web-facing computers out of all vendors this month, with 39,300 more than the previous month. OpenResty, which uses nginx, is serving 62,300 more active sites and now counts towards an additional 441 of the top one million sites. OpenResty was also counted on 6,640 more computers (+5.04%) than last month.
Apache has the greatest number of active sites and, by a narrow 1.03pp margin over nginx, the greatest share of the top one million sites. However, it shrunk in both of these metrics, losing 583,000 active sites and 2,130 of the top one million. Apache lost out in most other metrics too, with 756,000 fewer domains and just over 5 million fewer sites. It did, however, gain a few more computers over last month, but nginx’s large growth meant that Apache still lost market share in this measurement.
Microsoft saw declines in all metrics this month, losing 3.22 million sites (-7.13%), 156,000 domains (-1.75%), 118,000 active sites (-1.88%), and 7,620 computers (-0.57%). Microsoft also lost 1,000 sites from its share of the top million.
Although one of the smaller web servers on the market, LiteSpeed has frequently shown strong and consistent growth, with this month being no exception. It had the largest sites and active sites growth of all web servers in the March 2022 survey, gaining 1.92 million sites and 277,000 active sites.
Vendor news
-
Apache released version 2.4.53 of their httpd web server. This version contains security fixes for four different CVEs. The release also brings a number of general bug fixes. Apache also released bug patches for several versions of Tomcat.
-
OpenSSL released versions 3.0.2 and 1.1.1n of their cryptography library in order to patch against a high severity denial of service vulnerability. OpenSSL is used by both Apache and nginx, which together account for a majority of all sites, domains, and web-facing computers.
-
Microsoft Azure has expanded to a new region in the North of China. Microsoft’s share of the web server software market is much larger in China compared to the rest of the world, with 16.5% of active sites, 20.1% of domains, 13.4% of sites, and 15.0% of web-facing computers.
Developer | February 2022 | Percent | March 2022 | Percent | Change |
---|---|---|---|---|---|
nginx | 364,956,731 | 31.10% | 361,976,272 | 30.95% | -0.15 |
Apache | 277,928,961 | 23.68% | 272,919,651 | 23.33% | -0.35 |
OpenResty | 90,652,376 | 7.72% | 91,479,385 | 7.82% | 0.10 |
Cloudflare | 62,423,819 | 5.32% | 63,739,599 | 5.45% | 0.13 |