EasyApache 2017-11-07 Security Release

Posted by & filed under cPanel, Security.

SUMMARY
cPanel, Inc. has released updated RPMs for EasyApache 4 on November 7, 2017, with OpenSSL 1.0.2m. This release addresses vulnerabilities related to CVE-2017-3736 and CVE-2017-3735. We strongly encourage all OpenSSL users to upgrade to version 1.0.2m.

 

AFFECTED VERSIONS
All versions of OpenSSL through 1.0.2l

 

SECURITY RATING
The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs:

 

CVE-2017-3735 – LOW
OpenSSL 1.0.2m
Fix parse error in the IPAdressFamily extension related to CVE-2017-3735

 

CVE-2017-3736 – MEDIUM
OpenSSL 1.0.2m
Fix carry propagating bug in x86_64 Montgomery squaring procedure related to CVE-2017-3736

 

SOLUTION
cPanel, Inc. has released updated RPMs for EasyApache 4 on November 7, 2017, with an updated version of OpenSSL version 1.0.2m. Unless you have enabled automatic RPM updates in your cron, update your system with either yum update or WHM’s Run System Update interface.

 

REFERENCES
https://nvd.nist.gov/vuln/detail/CVE-2017-3736
https://nvd.nist.gov/vuln/detail/CVE-2017-3735
https://www.openssl.org/news/secadv/20171102.txt


EasyApache 2017-10-31 Security Release

Posted by & filed under cPanel, Security.

SUMMARY
cPanel, Inc. has updated RPMs for EasyApache 4 with PHP versions 5.6.32, 7.0.25 and 7.1.11, and released EasyApache 3.34.19 with PHP version 5.6.32 on October 31, 2017. This release addresses vulnerabilities related to CVE-2016-1283. We strongly encourage all PHP 5.6 users to upgrade to versions 5.6.32, all PHP 7.0 users to upgrade to version 7.0.25, and all PHP 7.1 users to upgrade to version 7.1.11.

 

AFFECTED VERSIONS
All versions of PHP 5.6 through 5.6.31
All versions of PHP 7.0 through 7.0.24
All versions of PHP 7.1 through 7.1.10

 

SECURITY RATING
The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs:

CVE-2016-1283 – HIGH
PHP 5.6.32
Fixed bug in PCRE related to CVE-2016-1283

PHP 7.0.25
Fixed bug in PCRE related to CVE-2016-1283

PHP 7.1.11
Fixed bug in PCRE related to CVE-2016-1283

 

SOLUTION
cPanel, Inc. has released updated RPMs for EasyApache 4 on October 31, 2017, with a updated versions of PHP versions 5.6.32, 7.0.25, and 7.1.11. Unless you have enabled automatic RPM updates in your cron, update your system with either yum update or WHM’s Run System Update interface.

cPanel, Inc. has released EasyApache 3.34.19 with an updated versions of PHP 5.6.32. Unless you have disabled EasyApache updates, the EasyApache application updates to the latest version when launched. Run EasyApache to rebuild your profile with the latest version of PHP.

 

REFERENCES
https://nvd.nist.gov/vuln/detail/CVE-2016-1283
http://www.php.net/ChangeLog-5.php
http://www.php.net/ChangeLog-7.php


EasyApache 2017-10-16 Security Release

Posted by & filed under cPanel, Security.

SUMMARY
cPanel, Inc. has released updated RPMs for EasyApache 4 on October 16, 2017, with a patch for Passenger. We strongly encourage all Passenger users to update their system to obtain the patch.

 

AFFECTED VERSIONS
All versions of Passenger

 

DESCRIPTION
This update patches a vulnerability where a user can list the contents of arbitrary files on the system when Passenger runs as the root user.

 

SOLUTION
cPanel, Inc. has released updated RPMs for EasyApache 4 on October 16, 2017, with a patch for Passenger. Unless you have enabled automatic RPM updates in your cron, update your system with either yum update or WHM’s Run System Update interface.

 

REFERENCES
https://blog.phusion.nl/2017/10/16/passenger-5-1-11/
https://blog.phusion.nl/2017/10/13/passenger-security-advisory-5-1-11/


Account DNS Check version 13 released

Posted by & filed under Announcements, cPanel.

We are pleased to announce version 13 of our Account DNS Check WHM plugin has been released! This release updates this plugin to use cPanels new API tokens for API calls since cPanel has deprecated the old accesshash authentication method. We also updated the UI in accordance to WHM’s new frame-less interface. This means the WHM header and sidebar will be present again when using this plugin.

You can upgrade in one of two ways.

  1. Log into the WHM and click on the Account DNS Plugin. You should see a new version notice, click the upgrade link!
  2. Log into your server as root via the console or SSH and run the following command /var/cpanel/addons/accountdnscheck/bin/upgrade

Please submit any bugs or issues to support@ndchost.com.  Thank you!


cPanel TSR-2017-0005 Announcement

Posted by & filed under cPanel, Security.

 

cPanel TSR-2017-0005 Announcement

cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system.

cPanel has rated these updates as having CVSSv3 scores ranging from 2.2 to 7.8.

Information on cPanel’s security ratings is available at https://go.cpanel.net/securitylevels.

If your deployed cPanel & WHM servers are configured to automatically update when new releases are available, then no action is required. Your systems will update automatically. If you have disabled automatic updates, then we strongly encourage you to update your cPanel & WHM installations at your earliest convenience.

RELEASES

The following cPanel & WHM versions address all known vulnerabilities:

66.0.23 & Greater
64.0.40 & Greater
62.0.30 & Greater
60.0.48 & Greater
56.0.52 & Greater

The latest public releases of cPanel & WHM for all update tiers are available at http://httpupdate.cpanel.net.

SECURITY ISSUE INFORMATION

The cPanel Security Team and independent security researchers identified the resolved security issues. There is no reason to believe that these vulnerabilities have been made known to the public. As such, cPanel will only release limited information about the vulnerabilities at this time.

Once sufficient time has passed, allowing cPanel & WHM systems to automatically update to the new versions, cPanel will release additional information about the nature of the security issues. This Targeted Security Release addresses 11 vulnerabilities in cPanel & WHM software versions 66, 64, 62, 60, and 56.

Additional information is scheduled for release on September 19, 2017.
For information on cPanel & WHM Versions and the Release Process, read our documentation at:
https://go.cpanel.net/versionformat

For the PGP-Signed version of this announcement please see: https://news.cpanel.com/wp-content/uploads/2017/09/TSR-2017-0005.announcement.signed.txt


cPanel TSR-2017-0003 Announcement

Posted by & filed under cPanel, Security.

cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system.

cPanel has rated these updates as having CVSSv3 scores ranging from 2.2 to 8.8.

Information on cPanel’s security ratings is available at https://go.cpanel.net/securitylevels.

If your deployed cPanel & WHM servers are configured to automatically update when new releases are available, then no action is required. Your systems will update automatically. If you have disabled automatic updates, then we strongly encourage you to update your cPanel & WHM installations at your earliest convenience.

RELEASES

The following cPanel & WHM versions address all known vulnerabilities:

64.0.21 & Greater
62.0.24 & Greater
60.0.43 & Greater
58.0.49 & Greater
56.0.49 & Greater

The latest public releases of cPanel & WHM for all update tiers are available at http://httpupdate.cpanel.net.

SECURITY ISSUE INFORMATION

The cPanel Security Team identified the resolved security issues. There is no reason to believe that these vulnerabilities have been made known to the public. As such, cPanel will only release limited information about the vulnerabilities at this time.

Once sufficient time has passed, allowing cPanel & WHM systems to automatically update to the new versions, cPanel will release additional information about the nature of the security issues. This Targeted Security Release addresses 24 vulnerabilities in cPanel & WHM software versions 64, 62, 60, 58, and 56.

Additional information is scheduled for release on May 16, 2017.
For information on cPanel & WHM Versions and the Release Process, read our documentation at:
https://go.cpanel.net/versionformat


HipChat Server is now available!

Posted by & filed under Announcements, Cloud Servers, Dedicated Servers.

 

HipChat Server image now available

for use on our Cloud and Dedicated servers!

 

We are pleased to announce that our Cloud Server platform now supports purpose built images and our first image is “HipChat Server v2.2.2”. HipChat is a popular team collaboration tool that allows your team to communicate with one another though 1-to-1 chat, group chat, or video chat. It also allows you to share files, screen share, and do a lot more.  For more information on HipChat, please visit their website at http://www.hipchat.com. Keep an eye out for more of our purpose built images as they become available. If you would like to see a specific App image feel free to send us a request to support@ndchost.com.

 

Deploying our HipChat server image.

  1. First step is to login to our customer portal by going to https://customer.ndchost.com.  If you do not know your login details they can be reset using the “forgot password” tool.
  2. From the top navigation menu click “My Services” and then “Services”.
  3. Next find your cloud server instance from the service list and click it.
  4. From the left sidebar, under “Server Manager” click “Deploy New Image”.
  5. Inside the “Choose an image” panel click “Latest Apps” and then select “HipChat Server”
  6. Set your primary disk size and choose a swap disk option
  7. Next you need to set a root password.  The HipChat server by default comes with root access disabled.  You should still set a password, however you will access the server using the same methods described in the HipChat server documentation.
  8. Click Deploy and wait for the server to start.

 

HipChat server first boot

It may take some time after your initial deploy for the HipChat server to come up.  The reason being that on first boot the HipChat server image runs a post installation script that prepares the server for use. You can expect to wait 5-10 minutes before being able to access HipChat’s web interface!


cPanel TSR-2017-0002 Full Disclosure

Posted by & filed under cPanel, Security.

SEC-208

Summary
Addon domain conversion did not require a package for resellers.

Security Rating
cPanel has assigned this vulnerability a CVSSv3 score of 2.7 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

Description
Previously, when you converted an addon domain to a normal account, it was not required that a reseller specify a package for the account creation. This allowed the reseller to use the system’s “default” package that has no account limits. Now, an addon domain conversion requires that a reseller have and specify a valid package for the account.

Credits
This issue was discovered by the cPanel Security Team.

Solution
This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-217

Summary

Self XSS Vulnerability in WHM cPAddons ‘showsecurity’ interface.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 4.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

When accessing the WHM cPAddons ‘showsecurity’ interface, the ‘addon’ parameter was not adequately escaped during page output. This could allow for arbitrary code to be injected into the rendered page.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-218

Summary

Arbitrary file read via WHM /styled/ URLs.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 6.0 CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Description

WHM supports /styled/ URLs in order to allow for reseller interface customization and branding. It is possible for these URLs to load and display content from a reseller’s home directory. These files were being loaded as the root user. This allowed for arbitrary files on the system to be read.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39

 

SEC-219

Summary

File overwrite when renaming an account.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 3.2 CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Description

When renaming an account it was possible to manipulate the security policy directories within the user’s home directory to overwrite certain files the user did not own.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-220

Summary

Arbitrary code execution during account modification.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 8.2 CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Description

When the primary domain of an account was changed in WHM’s “Modify an Account” interface, the .htaccess file in the account’s docroot was updated. This .htaccess update process included a syntax test, where it was possible for the cPanel user to execute arbitrary code as root.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-221

Summary

Arbitrary code execution during automatic SSL installation.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 8.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

During Autossl installation for user-controlled domains, the .htaccess file in the domain’s docroot was updated to bypass redirects that would interfere with the domain validation process. This .htaccess update process included a syntax test, where it was possible for the cPanel user to execute arbitrary code as root.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39

 

SEC-223

Summary

Security policy questions were not transfered during account rename.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 2.6 CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N

Description

If an account had security questions set up, and that account was renamed, the questions were not transferred to the renamed account correctly. This allowed an attacker to set up their own security questions by logging into the target account after an account rename was performed.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-224

Summary

cPHulk one day ban bypass when IP based protection enabled.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Description

It was possible under certain settings to never trigger a one day ban when IP-based protection was also enabled. Now, IP addresses are properly one day banned when the specified threshold is reached.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-225

Summary

Code execution as root via overlong document root path settings.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 8.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

By specifying a document root path which exceed Apache’s maximum configuration line length limit, it was possible for this excessive data to be interpreted as a new configuration directive. This could allow for an attacker to run arbitrary code as the root user.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-226

Summary

Arbitrary file overwrite via WHM Zone Template editor.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 6.8 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

Description

The WHM Zone Template editor interface did not properly validate the template filename when saving. This allowed resellers to overwrite arbitrary files on the system.

Credits

This issue was discovered by rack911labs.com.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-227

Summary

Expand list of reserved usernames.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 6.0 CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

Description

It was possible to create certain user accounts and then leverage the user’s home directory to enable various exploits. These account names have been added to the reserved username list.

Credits

This issue was discovered by rack911labs.com.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-228

Summary

Adding parked domains to mail config did not respect domain ownership.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 2.4 CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Description

It was possible for a reseller to add parked domains, that they did not own, to the Exim mail configuration. A reseller must now own the parked domain to perform any action on it.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-229

Summary

URL filtering flaw allowed access to restricted resources.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Due to faulty URL filtering, authenticated webmail accounts could access the PHPMyAdmin and PHPPGAdmin interfaces.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-232

Summary

Demo code execution via Htaccess::setphppreference API.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 7.4 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Description

The Htaccess::setphppreference API call was not restricted for demo accounts and accepted arbitrary data to be written into the account’s .htaccess file. This could allow for an attacker to execute arbitrary codeunder the demo account.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46

 

SEC-233

Summary

Arbitrary code execution for demo accounts via NVData_fetchinc API call.

Security Rating

cPanel has assigned this vulnerability a CVSSv3 score of 7.4 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Description

The NVData_fetchinc API call could accept an arbitrary filename to be included and processed by the cPanel engine. It was possible for an attacker to use this to execute arbitrary code under a demo account.

Credits

This issue was discovered by the cPanel Security Team.

Solution

This issue is resolved in the following builds:
11.62.0.17
11.60.0.39
11.58.0.45
11.56.0.46


cPanel TSR-2017-0002 Announcement

Posted by & filed under cPanel, Security.

cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system.

cPanel has rated these updates as having CVSSv3 scores ranging from 2.4 to 8.8.

Information on cPanel’s security ratings is available at https://go.cpanel.net/securitylevels.

If your deployed cPanel & WHM servers are configured to automatically update when new releases are available, then no action is required. Your systems will update automatically. If you have disabled automatic updates, then we strongly encourage you to update your cPanel & WHM installations at your earliest convenience.

RELEASES

The following cPanel & WHM versions address all known vulnerabilities:

11.62.0.17 & Greater
11.60.0.39 & Greater
11.58.0.45 & Greater
11.56.0.46 & Greater

The latest public releases of cPanel & WHM for all update tiers are available at http://httpupdate.cpanel.net.

SECURITY ISSUE INFORMATION

The cPanel security team and independent security researchers identified the resolved security issues. There is no reason to believe that these vulnerabilities have been made known to the public. As such, cPanel will only release limited information about the vulnerabilities at this time.

Once sufficient time has passed, allowing cPanel & WHM systems to automatically update to the new versions, cPanel will release additional information about the nature of the security issues. This Targeted Security Release addresses 15 vulnerabilities in cPanel & WHM software versions 11.62, 11.60, 11.58, and 11.56.

Additional information is scheduled for release on March 21, 2017.
For information on cPanel & WHM Versions and the Release Process, read our documentation at:
https://go.cpanel.net/versionformat


EasyApache 21 February 2017 Maintenance Release

Posted by & filed under cPanel, Security.

SUMMARY
cPanel, Inc. has released EasyApache 3.34.12 with Apache version 2.2.32. This release addresses vulnerabilities related to CVE-2016-8743 and CVE-2016-5387. We strongly encourage all Apache 2.2 users to upgrade to version 2.2.32.

 

AFFECTED VERSIONS
All versions of Apache 2.2 through version 2.2.31

 

SECURITY RATING
The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs:

 

CVE-2016-8743 – MEDIUM
Apache 2.2.32
Fixed bug related to CVE-2016-8743

 

CVE-2016-5387 – MEDIUM
Apache 2.2.32
Additional HTTPOXY mitigation related to CVE-2016-5387

 

SOLUTION
cPanel, Inc. has released EasyApache 3.34.12 with an updated version of Apache 2.2.32. Unless you have disabled EasyApache updates, the EasyApache application updates to the latest version when launched. Run EasyApache to rebuild your profile with the latest version of Apache.

REFERENCES
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-8743
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5387
http://www.apache.org/dist/httpd/CHANGES_2.2.32