Critical: exim security update

Discussion in 'Masalah Teknik dan Keamanan' started by gresshost, 10 Dec 2010.

Thread Status:
Not open for further replies.
  1. gresshost

    gresshost Poster 2.0

    Messages:
    125
    Likes Received:
    0
    Trophy Points:
    16
    Langsung copas dari email..mudah2an berguna ya :)
    -------------------------------------------------------------------
    A privilege escalation vulnerability exists in Exim, the mail transfer agent used by cPanel & WHM.

    -----------------------
    Security Rating
    -----------------------
    This update has been rated as Critical by the cPanel Security team.

    Description
    -----------------------
    Research up to this point indicates the exploit is a buffer overflow vulnerability that takes advantage of the default Exim configuration settings related to altering Exim's runtime configuration file along with overriding the macro definitions in the configuration file. This buffer overflow may lead to arbitrary code execution with the privileges of the user executing the Exim daemon. However, the Exim user retains root privileges when running the -C and -D command line flags. Through the creation of a temporary exim configuration which is processed with the -C or -D flags, the Exim user is able to execute arbitrary commands as root.

    Solution
    -----------------------
    To resolve and work around the issue, for Linux-based systems cPanel has issued new Exim RPMs. The new version of Exim locks configuration file locations to the /etc/exim prefix as well as disabling use of the -D flag. Server Owners are strongly urged to upgrade to the following Exim RPM versions:

    • Systems configured to use Maildir: Exim 4.69-25
    • Systems configured to use mbox (deprecated): Exim 4.63-4

    Exim RPMs will be distributed through cPanel's package management system. All cPanel & WHM servers receiving updates automatically will receive the updated Exim RPM during normal update and maintenance operations (upcp). If you prefer to install the update right now, please run the following in a root shell:

    /scripts/eximup

    On cPanel & WHM FreeBSD servers, Exim is an unmanaged install performed from the Ports system. To apply a like setup on FreeBSD systems, server administrators will need to perform the following manual configuration:

    • Remove WITHOUT_ALT_CONFIG_PREFIX=yes from /etc/make.conf
    • Add the following to /var/db/ports/exim/options

    WITH_ALT_CONFIG_PREFIX=true
    SEDLIST+= -e 's,^(ALT_CONFIG_PREFIX=).*,\1/etc/exim,'
    SEDLIST+= -e 's,^\# (DISABLE_D_OPTION=),\1,'

    • Change directory to /usr/ports/mail/exim
    • Execute 'make deinstall'
    • Execute 'make install'

    Caution: the above changes have potential to be undone by /scripts/checkmakeconf, and updates to the Exim port. An upcoming version of cPanel & WHM 11.28 will resolve this for FreeBSD users.
     
  2. nicosoftmedia

    nicosoftmedia (RIP) Community Guide

    Messages:
    2,025
    Likes Received:
    34
    Trophy Points:
    48
    Barusan saya juga dapat emailnya dari cPanel.
    Namun bila dilihat ini update hanya untuk freeBSD user.
     
  3. galuh82

    galuh82 Hosting Guru Web Hosting (Company)

    Messages:
    2,514
    Likes Received:
    186
    Trophy Points:
    63
    benar, itu untuk yang pake freebsd :)
     
  4. ekovirtua

    ekovirtua Expert 1.0

    Messages:
    648
    Likes Received:
    30
    Trophy Points:
    28
    Tenang saja untuk pengguna cPanel + centOS itu untuk freeBSD
     
  5. teguhaditya

    teguhaditya Poster 2.0

    Messages:
    157
    Likes Received:
    8
    Trophy Points:
    18
    untung masih setia pake centos
     
  6. hostingceria

    hostingceria Expert 1.0 Web Hosting

    Messages:
    673
    Likes Received:
    50
    Trophy Points:
    28
    kalau berdasarkan email diatas sepertinya tidak khusus freebsd tapi untuk semuanya, cuma yang freebsd caranya agak lain sendiri. buat jaga2 sih saya sudah update semua server
     
  7. gresshost

    gresshost Poster 2.0

    Messages:
    125
    Likes Received:
    0
    Trophy Points:
    16
    tul pak, itu utk smua server...utk freebsd agak beda caranya :)

     
  8. galuh82

    galuh82 Hosting Guru Web Hosting (Company)

    Messages:
    2,514
    Likes Received:
    186
    Trophy Points:
    63
    hmm .. salah ambil kesimpulan dong hee ..
    jadi untuk non-freebsd cukup dengan /scripts/eximup saja ya ?

    salam,
     
Loading...
Thread Status:
Not open for further replies.

Share This Page

Loading...