IceWarp Unified Communications Server User to User IceWarp Unified Communications Server User to User

Forums  Register  Login  My Profile  Inbox  Address Book  My Subscription  My Forums 

Photo Gallery  Member List  Search  Calendars  FAQ  Ticket List  Log Out

Any details on "critical security update" of 9.4.2?

 
Logged in as: Guest
Users viewing this topic: none
  Printable Version
All Forums >> [IceWarp Unified Communications Server Configuration] >> IceWarp Mail Server Configuration >> Any details on "critical security update" of 9.4.2? Page: [1]
Login
Message << Older Topic   Newer Topic >>
Any details on "critical security update" of ... - 5/6/2009 1:47:14 PM   
bserebin

 

Posts: 2
Score: 0
Joined: 7/14/2008
Status: offline
Hello All,

Does anyone know what specifically is wrong with 9.4.1 and earlier that caused IceWarp to release 9.4.2? The 9.4.2 release notes for "what's new" refer to 9.4.1.

From the IceWarp generated announcement email:
We highly recommend that you update your system today, as this vulnerability exists in versions 9.4.1 and earlier. Bear in mind that failure to upgrade will result in increased risk levels, varying from low to high.

Thanks,
-Ben

_____________________________

REEF Solutions
Technology Solutions Consulting
President / Network Consultant
Ben Serebin
www.reefsolutions.com

Founder / President
New York Exchange [Server] User Group
www.nyexug.com
Post #: 1
RE: Any details on "critical security update"... - 5/6/2009 5:21:48 PM   
wdgMax

 

Posts: 35
Score: 0
Joined: 4/2/2009
Status: offline
http://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses

Pretty lame of them to only give us one day to patch, IMHO.

-Max

(in reply to bserebin)
Post #: 2
RE: Any details on "critical security update"... - 5/6/2009 6:15:14 PM   
wdgMax

 

Posts: 35
Score: 0
Joined: 4/2/2009
Status: offline
Also, from the release notes:

9.4.2 (2009-04-17)

[-] 2009-04-17 SMS gateway - Possible access Violation problem fixed
[+] 2009-04-14 PHP - php_tidy extension added
[*] 2009-04-06 Groupware - FormatWhereItem() always uses additional braces
[*] 2009-04-06 Migration Engine - If login in the queue fails a permanent error is logged and use will not be retried
[-] 2009-04-06 DB Class - Proper connection termination
[*] 2009-04-06 DBClass - SanitizeDBSQL() - support for UNION and INTO operators added, these keywords are completely forbidden and must not be used and are considered as SQL injection attempts, tested
[+] 2009-04-06 icewarpphp - new function icewarp_sanitize_db_sql(sql, [magicquotes=false]) added and tested, should be used for SELECT fields, WHERE statement and ORDER BY statement
[*] 2008-04-06 Groupware - Attributes parameter - SQL Injection sanitization added
[+] 2008-04-06 DB - SanitizeDBSQL() - support for [] brackets added, used in SQLite and Access for field specification, tested
[+] 2008-04-06 Groupware - All OtherSelect and Where parameters sanitized with SanitizeDBSQL(), all string fields properly escaped, SQL injection save, tested
[*] 2008-04-06 DB - SanitizeDBSQL() - support for double quotes added
[+] 2008-04-06 DB - SanitizeDBSQL() - new function implemented and tested
[*] 2008-04-06 DB - QuarantineList() and GLList() functions - Flags SQL Injection sanitation added
[-] 2009-03-12 [#ZFJ-784222] Config - Size of Date selection dialog is determined automatically
[-] 2009-03-12 API - Multiprocessor support is not enabled in api.dll
[-] 2009-03-12 [#ZTI-488256] Request after starting merak causes Segmentation fault
[-] 2009-03-10 DB Class - termination routine from DB.dll is called again
[-] 2009-03-09 [#KZK-157937] - All services - If domain hash can not be created successfully, old domain hash is preserved
[-] 2009-03-02 AntiSpam - Auto delete old files in Spam folder - DeleteWithUpdate() applied - Directory cache properly used
[-] 2009-02-28 IMAP Service - COPY and APPEND commands respect the mailbox quota


(in reply to wdgMax)
Post #: 3
RE: Any details on "critical security update"... - 5/6/2009 6:15:31 PM   
bserebin

 

Posts: 2
Score: 0
Joined: 7/14/2008
Status: offline
Hello Max,

Thanks for the info. IceWarp alerted folks on 5/4, so yes, it wasn't much time.

Also, according to the vendor, only 9.4.1 is affected.

-Ben

_____________________________

REEF Solutions
Technology Solutions Consulting
President / Network Consultant
Ben Serebin
www.reefsolutions.com

Founder / President
New York Exchange [Server] User Group
www.nyexug.com

(in reply to wdgMax)
Post #: 4
Page:   [1]
All Forums >> [IceWarp Unified Communications Server Configuration] >> IceWarp Mail Server Configuration >> Any details on "critical security update" of 9.4.2? Page: [1]
Jump to:





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts


2001 - 2008 © IceWarp