WEBppliance 3.1.6 Security Update (LS)

Article ID: 2566 
Last Review: Oct,6 2008
Author: APPLIES TO:
  • Parallels Pro Control Panel Linux

Additional information

View Knowledge
Knowledge ID 1721
Product : WEBppliance for Linux
Version : 3.1.6
Topic : FAQ

Title
WEBppliance 3.1.6 Security Update (LS)

Summary
WEBppliance 3.1.6 Security Update (LS)

Prevention


Details

WEBppliance 3.1.6 provides a security update that resolves the predictable temporary file vulnerability in Python 2.2.1.

Compatibility :

This patch requires WEBppliance 3.1.5 for Linux to be installed on your server.

NOTE: This patch will not install on any other version of WEBppliance for Linux, other than 3.1.5.

Major Features of WEBppliance 3.1.6
This patch addresses and fixes the security vulnerability mentioned below:

  1. Predictable temporary file vulnerability in Python.
    os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.

    Advisory details for the security patch are available at the following URL:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1119


Installation Instructions :

Download site: (be sure to download using BINARY mode)
http://download.swsoft.com/ensim/download/webppliance/linux/patches/3.1.6/


To install the patch please follow the instructions below :

1.  Download the file LS-3.1.6-1.tar.gz

2.  Uncompress the file:
    tar -xvzf LS-3.1.6-1.tar.gz

3.  Change the current directory to the directory
    where you have uncompressed the file:
    cd LS-3.1.6-1

4.  Run the following command
    # sh ./patch-install-3.1.6-1.sh
    After checking that this is the LS installation for LWP 3.1.5, this
    install script would upgrade the required rpms (requires root access).


Attachments


Related Knowledge

Related Links
 
Last ModifiedUsageSatisfiedLast Used
8/20/2004 12:40:20 PM11 10/11/2007 6:53:24 AM
Subscription for this article changesSubscription for this article changes

Please provide feedback on this article

Did this article help you solve your issue?
Yes
No
Partially
I do not know yet
 
Strongly Agree   Strongly Disagree
  9 8 7 6 5 4 3 2 1
The article is easy to understand
The article is accurate
Additional Comments:
*Please provide us with your email address in case we need to contact you.
captcha *Please type the code you can see.
* - required fields