Linux Compatible

  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter

Advertisement


Latest News

[ Windows | Linux | Apple ]

· Google Chrome 6.0.472.53 released
· Kernel Update for RHEL
· New wireshark/barnowl packages for Debian
· WD TV Live Plus Media Player Review
· Apple posts iPad iOS 4.2 Coming Soon page
· Proxmox VE 1.6 released
· A Guide to Today's Top 10 Linux Distributions
· Apple Seeds Mac OS X 10.6.5 Build 10H535 to Developers
· NVIDIAs New GeForce 400M 3D Vision and Optimus Notebooks
· NHL2K11 for iPhone

Upcoming News

· Contest: Win a Samsung Gravity T or Samsung Flight II Cell Phone @ TestFreaks
· News: Nvidia fills out GeForce 400M lineup with seven mobile GPUs
· News item for consideration: Arctic Sound S111 Portable Speakers and C1 Mobile USB Charger Review
· Lian Li Pitstop PC-T60 Open Air Test Bench Review @ Legit Reviews
· [Tech ARP] How To Fix The PCI Express x1 Bug Rev. 3.2
· [Tech ARP] http://www.techarp.com/article/PCIe_X1_Bug/icon_big.png
· OCZ Vertex 2 60GB SSD
· Lenovo ThinkPad T410s Review @ TechReviewSource.com
· Tom Clancy H.A.W.X. 2 Review (Xbox 360) @ KitGuru Gaming
· REVIEW: IRISCard Anywhere 4 | Business Computing World

Linux Compatibility

· Acer Aspire Timelinex 5820tg
· Notebook GX620
· IBM Thinkpad R50e
· BricsCAD for Linux
· Sil 3512 - Silicon Image Serial ATA (SATA) controller
· AverMedia AVerTV Volar Black HD (A850)
· SyncMaster B1930 monitor
· ATI Radeon 9600 Pro
· Compaq Presario CQ40
· Aspire 5741

New Forum Topics

· Warhammer 40k Chaos Gate on XP - help?
by: Nateski
on: 2010-09-03 14:13
113 replies, 95712 views

· Need for Speed II: SE problem with Windows XP
by: nullphobiamaddy
on: 2010-08-31 18:46
5 replies, 20328 views

· mouse stops working once windows xp loads...help
by: cole1434
on: 2010-08-30 05:28
6 replies, 1099 views

· Dungeon Keeper 2 on vista
by: littlecengiz
on: 2010-08-26 08:47
1 replies, 974 views

· Best firewall/antivirus/antispyware combo
by: joebiden
on: 2010-08-20 11:17
11 replies, 27075 views

News Channels

· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS

What's New

Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » July 2010 » ispCP Omega 1.0.5 Security Announcement II

ispCP Omega 1.0.5 Security Announcement II

Posted by: Philipp Esselbach on: 07/30/2010 01:02 PM [ Print | 0 comment(s) ]

Another small vulnerability has been discovered in ispCP Omega 1.0.5 while running in DEBUG mode




Today we discovered another fault, this time in the ispCP Omega Engine if DEBUG is set to 1 in ispcp.conf. (System default is 0.)

On Database backup the password for the ispCP database user is shown and logged in clear text, while logs are world readable. It is recommended to fix this bug by either set DEBUG to 0 or use the patch attached to ticket 2411.

An Identical security hole was discovered today in these scripts:

engine/backup/ispcp-backup-all
engine/backup/ispcp-backup-ispcp

The patch attached to the ticket #2411 was updated today.

Also, it's recommended to remove all the /var/log/ispcp/* log after fixing this security hole by setting debug mode to 0, or by applying the patch. For versions prior to ispCP 1.0.5, it's strongly recommended to migrate and to apply the patch.

Note: For the last script, it's really more important because this time, it's the main SQL account login (eg. SQL root account) credentials that is stored in cleartext.

We apologize for any inconvenience caused.


ispCP Omega 1.0.5 Security Announcement II


Bookmark and Share

Related Stories

07/25/2010 06:46 PM: ispCP Omega 1.0.5 Security Announcement by Philipp Esselbach
A security patch has been released for ispCP Omega 1.0.5...

03/01/2010 11:04 AM: ispCP Omega 1.0.4 Released by Philipp Esselbach
ispCP Omega 1.0.4 has been released...

12/20/2009 11:38 AM: ispCP Omega 1.0.3 Released by Philipp Esselbach
ispCP Omega 1.0.3 has been released...

02/26/2009 08:35 PM: ispCP Omega v1.0.0 Stable released by Philipp Esselbach
ispCP Omega v1.0.0 Stable has been released...

08/06/2008 12:47 PM: ispCP Omega 1.0.0 RC6 released by Philipp Esselbach
ispCP Omega 1.0.0 RC6 has been released...

03/17/2008 11:08 AM: ispCP Omega 1.0.0 RC4 by Philipp Esselbach
ispCP Omega 1.0.0 RC4 has been released...


« java-1.4.2-ibm security update · CompatDB Updates 07/30/10 »

Linux Compatible » News » July 2010 » ispCP Omega 1.0.5 Security Announcement II
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2010 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition