Ubuntu: 1968-1: Linux kernel vulnerabilities
(Sep 27) Several security issues were fixed in the kernel.
(Sep 27) Several security issues were fixed in the kernel.
(Sep 6) Several security issues were fixed in the kernel.
(Sep 6) Several security issues were fixed in the kernel.
(Sep 5) Several security issues were fixed in the kernel.
(Sep 6) Several security issues were fixed in the kernel.
(Sep 6) Several security issues were fixed in the kernel.
(Sep 6) Several security issues were fixed in the kernel.
(Sep 6) Several security issues were fixed in the kernel.
(Sep 6) Several security issues were fixed in the kernel.
(Sep 6) Several security issues were fixed in the kernel.
The following issues have been fixed:
[-] Administrators were unable connect to remote MySQL servers if their passwords contained the ampersand (“&”) symbol. (141662)
[-] Panel failed to back up subscriptions with additional vhost/ssl/nginx settings with XML-unescaped symbols (141708)
[-] (Linux only) Panel did not concatenate chained certificates bundles provided by Geotrust to the main certificate in the nginx configuration. (113865)
[-] Customers could not use the controls on the “File Sharing” tab if they set the preferred domain with the “www” prefix.
[-] (Linux only) Customers could not access the “File Sharing” tab after Panel was upgraded to version 11.5 if client.id for the administrator was not 1. (141589)
[-] File sharing did not work for domains with international domain names.
[-] (Linux only) PhpMyAdmin failed to export databases with the error “502 Bad Gateway” (141734)
[-] (Linux only) Some upgrade scripts failed if the client.id for administrator was not 1. (141589)
(Aug 29) Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, information leak or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems: [More…]
(Aug 20) Several security issues were fixed in the kernel.
(Aug 20) Several security issues were fixed in the kernel.
[*]Security improvements.
The following issues were resolved:
[-](Linux only) Virtual host templates stopped working after installation of Plesk 11.0.9 Update #57 (141716)
[-]Websites could not be opened in the Presence Builder editor if they used the Commenting module and the corresponding Disqus accounts were inaccessible. (117507)
[-](Linux only) Plesk API incorrectly reported about removed packages. (126317)
[-](Linux only) Execution of statistics calculation for a single domain resulted in the deletion of FTP log records for other domains.(122407)
(Aug 20) Several security issues were fixed in the kernel.
(Aug 20) Several security issues were fixed in the kernel.
The following issues have been fixed:
[-] (Linux only) Customers could receive the “Mail Not Delivered” messages even if their email was delivered successfully. (119925)
[-] (Linux only) The virus definitions of Parallels Premium Antivirus by Dr. Web were not updated if the default trial license key was used. (139833)
[-] (Linux only) After Panel was upgraded from version 11.0, PHP scripts could no longer be processed by nginx if SELinux was turned on. The following error was recorded in /var/log/php-fpm/error.log: “php-fpm.sock failed (13: Permission denied)”. (140941) [-] (Linux only) In some cases, Panel did not validate DNS record conflicts if CNAME records were manually modified. The DNS server failed to start. (141147)
[-] (Linux only) The RoundCube webmail was not working due to various errors (PHP errors, memory exhaustion, and so on) if certain classes or functions such as ini_get were disabled in the server-wide php.ini file. (141201)
[-] (Linux only) After upgrading Plesk from version 9.5, customers could no longer back up domains that had subdomains. The following error occurred: “Cannot savedir: Permission denied”. (141214)
[-] (Linux only) The subscription command-line utility could not change the PHP handler for websites. (141238)
[-] (Linux only) Subscriptions could not be synchronized with a service plan if the plan was created using command-line utilities and access to shell was not allowed or was set to chroot. (141254)
[-] (Linux only) The allow and deny access directives of Apache .htaccess worked incorrectly if a reverse proxy in nginx was enabled. (141265)
[-] (Linux only) If Panel was installed without updates, and updates were installed afterwards, email messages could not be sent. The following error occurred: “Warning: the Postfix sendmail command must be installed without set-uid root file permissions”. (141283)
[-] (Linux only) Administrators were unable to turn off the nginx reverse proxy. The following error occurred: “Service /etc/init.d/nginx failed to stop”. (141297)
[-] (Linux only) Customers could not disable DomainKeys email signing on domains after it had been enabled. (141316)
[-] The help page of the dns command-line utility was not localized. (141368)
[-] The help page of the server_dns command-line utility contained errors. (141374)
[-] Backing up to external FTP repositories did not work properly. (141100 and 141338)
[-] Updating of reseller service plans via API-RPC could result in the following error: “PHP Fatal error: Call to undefined method”. (141439)
[-] After upgrading from Plesk 9 it was impossible to remove email accounts with mail forwarding. The following error occurred: “PHP Fatal error: Call to undefined method”. (141453)
[-] Customers could use webmail on their domains even if the domains were suspended. (84187)
[-] (Linux only) Qmail did not accept email messages sent to mailing lists on domain aliases. The following error occurred: “550 sorry, no mailbox here by that name. (#5.7.17)”. (107619)
[-] (Linux only) Panel failed to migrate the Mailman data and settings if the default locale of the source server was German. (133147)
[-] Panel failed to migrate mail relay settings from Plesk 9.x with the error “Unable to set relaying type”. (140277)
[-] (Linux only) Panel failed to migrate databases that use latin-1 character set. In the migrated databases, non-ASCII characters were replaced with question marks. (141027)
[-] Panel did not pass database user passwords to event handlers. (141261)
[-] (Linux only) When administrators executed the statistics utility for a single domain, Panel removed FTP log records for other domains. (141378)
[-] Email notifications about resource overuse that were sent on behalf of the administrator contained wrong sender email addresses. (141380)
[-] Administrators had to complete the post-install configuration of Panel before they could use the server_dns command-line utility. (141502)
[-] Security improvements. (141537)
[-] (Linux only) Kaspersky Antivirus could not be switched on via the API-RPC. (141491)
[-] (Linux only) Message submission did not work after installing updates on Panel 11.5.30. (141740)
[-] (Windows only) Domains could not be migrated from Plesk 9 if mail accounts on source servers had a password containing a quotation mark (“) (141054)
[-] (Windows only) AWStats statistics processed log files very slowly because of excessive DNS lookups. (137500)
[-] (Windows only) IP addresses that were no longer used could not be removed from the server IP pool. The following error occurred: “The IP address x.x.x.x is already used for hosting”. (141139)
[-] (Windows only) Panel did not include some DNS records from the server-wide DNS template into DNS zones of newly created domains. (132577)
[-] (Windows only) Users were unable to log in to Control Panel from Customer & Business Manager by clicking Business Operations > Subscriptions > <subscription name> > Log In. They encountered the following error: “Internal error: SQLSTATE[42S22]: Column not found: 1054 Unknown column ‘externalId’ in ‘where clause’.” (141454)
[-] (Windows only) Users were unable to import database backups through phpMyAdmin. (141524)
(Aug 20) Several security issues were fixed in the kernel.
(Aug 20) Several security issues were fixed in the kernel.
(Aug 20) Several security issues were fixed in the kernel.
(Aug 20) The system could be made to expose sensitive information.
The following features have been improved:
The following issues have been fixed:
[-] (Linux only) Data transfers from Plesk failed if a source server had an APS application and an SSL certificate installed on the main domain. The following error was encountered: “Line 2519 error: Element ‘certificates’: This element is not expected.” (138313)
[-] (Linux only) Configuration generated successfully for domains with the frame forwarding hosting type which were not assigned any IP addresses. (72945)
[-] (Linux only) Newly created domains were not accessible if Panel installation was moved to a new directory with a symbolic link from the old installation’s location. (78435)
[-] Panel UI processed operations with the list of customers very slowly if at least one customer had a large number (more than a thousand) of subscriptions. (93163)
[-] After upgrading from Plesk 9.5.4, the turned off mail forwarding operation became active again. (100438)
[-] (Linux only) Plesk Mobile Manager for iPhone was unable to connect to Panel. (114780)
[-] (Linux only) When Migration & Transfer Manager was trying to download data from the source server, the transfer operation could fail with the message: “Error: pmm utility ‘migration_handler’ raised an exception. Error code is: 1” (140299)
[-] (Linux only) The domain command-line utility failed to enable the mail service for a domain if this domain had been created while no mail service had been installed in Panel. Panel issued the message: “PHP Fatal error”. (140833)
[-] (Linux only) Administrators could not adjust mail server settings in Administrator’s Panel after switching from Qmail to Postfix if short mail account names were allowed in Qmail settings. (140837)
[-] (Linux only) After upgrading to Panel 11.5, Panel failed to generate the Apache configuration files if the PHP setting max_execution_time was set to “0”. Panel raised the error: “Template_Exception: Syntax error on line 64”. (140853)
[-] (Linux only) The command-line utilities domain and subscription raised errors on attempts to obtain information about domains with hosting type “No hosting”. (140924)
[-] Subscriptions suspended due to traffic overuse were not automatically unsuspended at the beginning of the next month. (140939)
[-] Customers without subscriptions could not use the Panel’s built-in search. They encountered an “Internal error”. (140989)
[-] (Windows only) Panel displayed an unclear error message on the File Sharing page if the system user account was changed or removed by administrator in the operating system settings. (105470)
[-] (Windows only) The installation of the Formmail APS application failed with the error: “Error: Installation of formmail at http://example.com/formmail failed.” (132784)
[-] (Windows only) AWStats did not calculate web statistics for a domain with the WWW prefix and all the domain’s aliases. (140882)
[-] (Windows only) Certificate signing requests could not be generated properly via Plesk XML-RPC API. (140900)
[-] (Windows only) Customers were unable to retrieve a forgotten password from Panel if Panel was configured to work with Microsoft SQL Server. They encountered the “Operation failed” error. (141099)
Rank Performance Graph OS Outagehh:mm:ss FailedReq% DNS […]
The following issues have been fixed:
[-] (Linux only) Panel displayed confusing error messages when restoring backups created by Panel 9.5.4. (69420)
[-] After upgrading from Plesk 8.x or 9.x, mail users of a customer’s subscription could access other subscriptions of the same customer. (72902)
[-] Panel sent summary reports (Home > Tools & Settings > Summary Report) by email in plain text although they were supposed to be HTML pages. (139652)
[-] Administrators could not include domain names in the files of the default virtual host template using the @domain_name@ variable. (140092)
[-] (Linux only) Administrators could not create more user accounts after a successful creation of a large number of accounts (over 3000) because the allowed memory size was exhausted. (140167)
[-] Panel failed to save personal FTP repository settings if users specified a Directory for backup files storage that starts with ‘/’. (140209)
[-] Resellers could set resource limits of their customer’s subscriptions so that these limits would exceed the limits of resources available to the resellers. (140389)
[-] Customers could change their Preferred domain even if they did not have the Domain management permission. (140480)
[-] (Linux only) When administrator ran vzpkg update on a Parallels Virtuozzo Container with Panel, the following error occurred: “Dependencies cannot be resolved”. (140610)
[-] (Linux only) Users could not delete wildcard subdomains with mail service switched on. (138504)
[-] (Linux only) Panel failed to update and upgrade if PHP from the Webtatic repository was installed on the server. (138635)
[-] Panel did not warn users that all website content will be removed when they switched their domains’ hosting type from Website hosting to Forwarding or No web hosting. (140731)
[-] Security improvements. (140797)
[-] (Linux only) The statistics utility failed to calculate statistics for additional domains and subdomains. (140746)
[-] (Linux only) Administrators could not retrieve additional Parallels Premium Antivirus license keys through the Panel GUI. (140803)
[-] (Linux only) Customers could not set the value of the max_execution_time PHP setting to 0. The following error occurred: “Template_Exception: Syntax error on line 64 of /etc/apache2/plesk.conf.d/vhosts/.conf: FcgidIOTimeout must be greater than 0”. (140849)
[-] (Windows only) Administrators were unable to create domains with international domain names by means of API RPC or command line utilities if the Panel mail server supported ‘mbox_quota’ or ‘total_mboxes_quota’ limits (for example, the IceWarp Merak mail server). (71958)
[-] (Windows only) Panel failed to migrate data from Plesk 8.x or 9.x if Apache was running on the source server. (91307)
[-] (Windows only) Panel incorrectly transferred DNS SRV records when transferring domains from Panel 10.4.4. (139162)
[-] (Windows only) Administrators could not switch on the option Always assign one application pool to each subscription on the Tools & Settings > IIS Application Pool > Global Settings page if there was at least one subscription with the Forwarding hosting type on the server. (140363)
[-] (Windows only) Panel failed to restore system users from backups if the users’ passwords contained the symbol ” (double quote). (140394)
[-] (Windows only) Additional administrators could not add mass email templates. Panel raised the error “500 – Internal server error. There is a problem with the resource you are looking for, and it cannot be displayed.” (140478)
[-] (Windows only) When transferring data from another server, Panel failed to transfer mail content of mailboxes that had subfolders within the Inbox folder. (140616)
[-] (Windows only) The utility web_statistics_executor.exe stopped generating web statistics for all domains if an error occurred while processing a domain. (140717)
[-] (Windows only) Panel failed to migrate FTP accounts created for subdomains from Plesk 9.5. The following error occurred: “Unable to create FTP account: There are no available resources of this type (additional FTP accounts) left. Requested: 1; available: 0.” (140725)
(Jul 29) Several security issues were fixed in the kernel.
(Jul 29) The system could be made to crash or run programs as an administrator.
(Jul 29) The system could be made to crash or run programs as an administrator.
(Jul 30) The system could be made to crash or run programs as an administrator.
(Jul 29) The system could be made to crash or run programs as an administrator.
60 queries. 8.75 mb Memory usage. 1.286 seconds.