escapebox logo title
 
Information
Introduction
Specifications
MODUS technology
Domain registration
Prices
Billing
B2B reseller options
Consulting
Contact
About us
Imprint · Impressum
Business terms · AGB
Press room
Customer gallery
Glossary
Search


Action
Test-drive a box!
Order
· First box
· Additional box
· Domain registration
· Domain transfer
· Subdomain
· SSL certificate
· Cust. gallery entry
· Something else
Update CC info
Send auth'ed message
Get help
Talk back to us


Box Docs
Introduction
First steps
User accounts
Email/News service
Web service
Other software
Server protection
News/Changes
· Recent
· Archive


Recent Changes
· Security upgrade to libxml2 2.6.32 + patches
· Security upgrade to SquirrelMail 1.4.16
· Maintenance upgrade to Wget 1.11.2
· Security patches for PHP 5.2.6
· Maintenance upgrade to PHP 4.4.9
· Security patches for Python 2.4.5 & 2.5.2
· Maintenance upgrade to Python 2.3.7
· Maintenance upgrade to Bash 3.2.39
· Maintenance upgrade to Ruby 1.8.6p287
· Maintenance upgrade to cURL 7.18.0


Statistics
Active boxes 522  
Net I/O (30d) 362  GB
Disk space 274  GB


Latest Awards
webhostlist availability logo


modus technology logo

cauce member logo


Copyright © 2002-2008
EscapeBox Germany
     
Security upgrade to tiff 3.7.1 2004-12-23
More security vulnerabilities have been found in the 'tiff' library. We fixed the problem by upgrading to revision 3.7.1.


Maintenance upgrade to Multitail 3.4.2 2004-12-20
The new stable branch 3.4.x of Multitail is a merge between the previous stable branch 3.2.x and development code from 3.3.x. It introduces a number of improvements, and of course bug fixes.


Maintenance upgrade to Slrn 0.9.8.1 2004-12-20
This is a maintenance release which introduces some minor bug fixes and improvements.


PHP accelerator re-enabled 2004-12-18
We received information that there is actually no incompatibility between PHP 4.3.10 and the PHP accelerator we use. Instead, the pre-compiled script files in the accelerator's disk cache have been incompatible with PHP 4.3.10. That is, they just needed to be re-compiled with 4.3.10.

In our case, purging the disk caches in all boxes fixed the problem at once. These caches are going to fill up again on the fly as PHP scripts get requested over time. So, operation is back to normal now.


Security upgrade to PHP 4.3.10 2004-12-17
Several very serious security issues have been found in PHP versions up to 4.3.9. We fixed the problem by upgrading to revision 4.3.10 (incl. some patches that correct newly introduced flaws).

Unfortunately, we had to disable the PHP accelerator since it turned out to be incompatible with the new PHP4 version. In fact, according to PHP's bug tracking system all accelerators currently available break PHP 4.3.10. We will upgrade and re-enable the accelerator when a fixed version gets released.

In order to reliably activate the new version for all running instances of PHP4 we rebooted the server boxes (just a 15 seconds soft reboot).

For more information please refer to
  http://www.php.net/release_4_3_10.php


Maintenance upgrade to OpenSSH 3.9p1 2004-12-16
Just a number of minor bug fixes. There were no changes in functionality we know of.


Security upgrade to VIM 6.3.45 2004-12-16
Several vulnerabilities related to the use of options in modelines have been found in VIM. They could potentially result in a local user escalating privileges. We fixed the problem by upgrading to revision 6.3.45.


Maintenance upgrade to OpenSSL 0.9.7e 2004-12-16
This maintenance release contains a small number of nevertheless important bug fixes. There were no changes in functionality we know of.


Maintenance upgrade to Razor-agents 2.67 2004-12-13
Some of the changes and bug fixes introduced by revision 2.67 help improve the spam detection accuracy considerably.


Security patch for mod_access_referer 2004-12-13
A NULL pointer dereference bug has been found in mod_access_referer that could cause a remote DoS vulnerability. We fixed the problem by applying the recommended patch.


Upgrade to MySQL 4.0.22 2004-12-13
MySQL 4.0 is now our default version. Users who have been using MySQL 3.23 in the past will continue to do so by means of a number of symlinks installed in their boxes. For upgrade instructions please refer to '/usr/local/mysql-3.23/upgrade/README'.


Security patch for Zip 2004-12-03
There is a buffer overflow in Zip 2.3 and possibly earlier versions. When using recursive folder compression, the bug allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname. We fixed the problem by applying the recommended patch.

For more information please refer to
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1010


Kernel security patch 2004-12-03
A programming error has been found in FreeBSD's implementation of the 'procfs' filesystem (usually mounted as '/proc'). A malicious local user could perform a local denial of service attack by causing a system panic, or he could read parts of kernel memory.

We fixed the problem by applying the recommended patch. In order to activate the new UNIX kernel we had to reboot all of our servers. We apologize for the short service interruption.

For more information please refer to
  ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:17.procfs.asc


Security upgrade to Sudo 1.6.8p4 2004-11-26
Besides a number of bug fixes and improvements this release also corrects a potential security flaw that could allow a malicious user to run arbitrary commands in conjunction with Bash, due to insufficient environment sanitizing.


Maintenance upgrade to Pavuk 0.9.31 2004-11-26
This is a maintenance release which introduces some minor bug fixes and improvements.


Security patch for Cyrus IMAPD 2004-11-23
During an audit of Cyrus IMAPD several vulnerabilities were discovered which can lead to remote execution of arbitrary code. In the version of Cyrus IMAPD currently installed only one of these bugs existed, though. We fixed the problem by applying the recommended patch.

For more information please refer to
  http://security.e-matters.de/advisories/152004.html


Security upgrade to phpBB 2.0.11 2004-11-19
A potentially serious vulnerability in conjunction with the highlighting feature has been found in phpBB. We fixed the problem by upgrading to revision 2.0.11, which also contains other minor bug fixes and improvements. Note that if you previously ran revision 2.0.8, 2.0.9 or 2.0.10 there is no upgrade procedure necessary.


Security patch for Fetch 2004-11-19
The 'fetch' utility is a FreeBSD tool for fetching files via FTP, HTTP, and HTTPS. An integer overflow condition in the processing of HTTP headers has been found which can result in a buffer overflow. A malicious server or CGI script can respond to an HTTP or HTTPS request in such a manner as to cause arbitrary portions of the client's memory to be overwritten, allowing for arbitrary code execution. We fixed the problem by applying the recommended patch.

For more information please refer to
  ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:16.fetch.asc


Security patch for SquirrelMail 1.4.3a 2004-11-09
An XSS scripting flaw has been found in SquirrelMail. We fixed the problem by applying the recommended patch.


Maintenance upgrade to PostgreSQL 7.3.8 2004-10-29
This maintenance release corrects some minor bugs. There is also a security fix included regarding a symlink attack on temporary files. However, this is of no relevance to our system since the affected script is not installed in our setup.


Security upgrade to Apache 1.3.33 2004-10-29
A buffer overflow in the 'get_tag' function in 'mod_include' for Apache 1.3.x allows local users who can create SSI documents to execute arbitrary code as the Apache user via SSI (XSSI) documents that trigger a length calculation error.

We fixed the problem by upgrading to Apache 1.3.33. In order to reliably activate the new version for all running instances of Apache we rebooted the server boxes (just a 15 seconds soft reboot).

For more information please refer to
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0940


Maintenance upgrade to mod_jk 1.2.6 2004-10-29
This is a maintenance release which introduces some minor bug fixes and improvements.


Patch for Apache 1.3.32 2004-10-28
In Apache 1.3.32, a change in 'mod_rewrite' introduced a new bug. For requests forwarded through 'mod_proxy' (flag 'P') the query string, if available, will be appended twice, which usually results in a 404 response. We corrected the problem for now by applying a local patch which effectively backs out the faulty fix.

For more information please refer to
  http://nagoya.apache.org/bugzilla/show_bug.cgi?id=14518


Security upgrade to libxml2 2.6.15 2004-10-28
A number of buffer overrun bugs, in part remotely exploitable, have been found in libxml2. We fixed the problem by upgrading to revision 2.6.15.


Maintenance upgrade to Apache 1.3.32 2004-10-26
In Apache 1.3.32, a number of bugs have been fixed since the latest (security) release 1.3.31. So we upgraded to the new revision now. This is a bug fix release, and there were no changes in functionality we know of.

Please note that the mod_proxy security issue (CAN-2004-0492) mentioned in Apache's ChangeLog had been corrected already in our system (on 2004-06-12).


Kernel maintenance 2004-10-21
Besides the usual pile of kernel bug fixes and improvements from both the FreeBSD project and our todo list we also corrected a long-standing flaw in FreeBSD's TCP stack (ignored RST packets during connection shutdown), which we deem important enough to justify a kernel update at this point. In order to activate the new UNIX kernel we had to reboot all of our servers. We apologize for the short service interruption (less than 10 minutes).


Extended on-the-fly compression for web content 2004-10-15
So far, on-the-fly compression for web content has been enabled in our default setup for static HTML pages (incl. SSI), CGI scripts and PHP. We now added 'mod_gzip' support also for the output generated by some of the optional Apache modules, namely 'mod_fastcgi', 'mod_perl', 'mod_python' and 'mod_jk' (Tomcat via Apache).

In case you have a private copy of '/box/bin/httpd.conf.eperl' in your server box, in order to benefit from this change, too, you would just need to add the following lines to the config section of 'mod_gzip':
  mod_gzip_item_include       handler ^fastcgi-script$
  mod_gzip_item_include       handler ^perl-script$
  mod_gzip_item_include       handler ^python-program$
  mod_gzip_item_include       handler ^jakarta-servlet$
As always, for a more complete synchronization with our default setup the original shared, non-overlayed files can be found under '/system/sd'.


Security patch for tiff 3.6.1 2004-10-14
Multiple heap-based buffer overflows have been found in the 'tiff' library image decoding routines, potentially allowing the execution of arbitrary code with the rights of the user viewing a maliciously crafted image. We fixed the problem by applying the recommended patch.


Security flaw in Cyrus-SASL 2004-10-08
Two problems have been found in Cyrus-SASL. Under certain conditions it is possible for a local user to exploit a vulnerability in the way the SASL_PATH environment variable is honored. The second bug, a remote buffer overflow in the 'digestmd5.c' file, does not apply to our revision of Cyrus-SASL. We applied the recommended patches.


New package: Jakarta-Tomcat 5.0 2004-10-01
In addition to Jakarta-Tomcat 3.3 and 4.1 we installed revision 5.0.28 in order to also support Servlet/JSP specs 2.4/2.0. Which Tomcat server gets started at boot time depends on what startup script is in place. 'mod_jk' works with any of them.


Maintenance upgrade to PHP 4.3.9 2004-09-30
This maintenance release fixes more than 50 bugs that have been discovered and resolved since the 4.3.8 release.


Maintenance upgrade to PostgreSQL 7.3.7 2004-09-16
Due to insufficient interlocking between transaction commit and checkpointing, it was possible for transactions committed just before the most recent checkpoint to be lost, in whole or in part, following a database crash and restart. This is a serious bug that has existed since PostgreSQL 7.1. We fixed the problem by upgrading to revision 7.3.7.


Maintenance upgrade to FreeBSD 4.10 2004-09-15
Our FreeBSD kernel has been in sync for a while now with the latest revision in the 4-STABLE branch (4.10), so at this point we upgraded Userland to 4.10 as well. From the user's perspective the changes will be hardly noticeable. Most are "under the hood", and in this development branch new features are generally implemented with compatibility in mind. Also, the actual application software packages (web, email etc.) are not affected by this upgrade since they are separate from the base system.

In order to bump up the version number to 4.10 (hard-wired in the kernel) we had to reboot all of our servers. We apologize for the short service interruption (less than 15 minutes).


Attack on SSH service averted 2004-09-12
Some of our users may have noticed that the server load went up today for a short period of time. Some lowlife on a probably hacked server (80.190.240.3) pounded our operation with SSH connection attempts. That is, apparently not our servers in particular, but rather whatever he found within the IP block our gear is assigned to. We have no information at this point on whether this was just a DoS attack (server overload) or a brute force password guessing attempt.

In any case, we lost no time and blocked the IP traffic coming from that address. The attack ceased, the load went down, our pagers fell silent, end of story. Have a nice weekend. :-)


Security upgrade to ImageMagick 5.5.7.30 2004-09-08
A buffer overrun bug associated with decoding runlength-encoded BMP images has been found in ImageMagick. This vulnerability could be exploited to execute arbitrary code on an affected system. We fixed the problem by upgrading to revision 5.5.7.30.


Maintenance upgrade to RRDtool 1.0.49 2004-09-02
Besides adding a number of new features this is mainly a bug fix release. This is the tool that maintains the round robin box usage database which is part of each server box, and also generates the statistics diagrams.


Maintenance upgrade to phpBB 2.0.10 2004-09-02
This is basically a bug fix release. Note that if you previously ran revision 2.0.8 or 2.0.9 there is no upgrade procedure necessary.


Kernel update 2004-09-01
Besides fixing two minor information leaks in conjunction with the 'arp' and 'route get' commands we have an adaptive congestion avoidance mechanism in place now that reduces packet loss and timeouts on slow dial-up lines (modem, ISDN) without compromising on speed with faster access technologies (DSL, cable and better).

Also, an ample amount of other fixes and improvements from our todo list went into this update as well. In order to activate the new UNIX kernel we had to reboot all of our servers. We apologize for the short service interruption (less than 10 minutes).


Maintenance upgrade to Mytop 1.4 2004-08-31
Besides adding some new features this is mainly a bug fix release.


Clarification about Zlib DoS issue 2004-08-31
Currently there are reports stating that the Zlib compression library (revision 1.2 or later) contains a vulnerability that can be used for local and remote DoS attacks. Please note that in our system the Zlib shared library is part of the FreeBSD base installation, is currently at revision 1.1.4 and is therefore not affected. However, users with privately installed software may want to investigate this issue in their realm, too.

For more information please refer to
  http://www.securitytracker.com/alerts/2004/Aug/1011085.html


Maintenance upgrade to Portupgrade 20040701 2004-08-21
FreeBSD's ports repository maintainers recently introduced an extended 'INDEX' file format (additional fields). In order to stay in sync with this change we upgraded the Portupgrade tools to revision 20040701 now. Please note that this is of relevance only to those who happen to have a copy of said repository installed under '/usr/ports'.


Security flaw in Ruby 2004-08-21
A problem has been found in the CGI session management of Ruby. CGI::Session's FileStore implementations store session information insecurely. They simply create files, ignoring permission issues. This can lead an attacker who has also shell access to the webserver to take over a session. We fixed the problem by upgrading Ruby 1.6.8 to the latest snapshot as of 2004-07-28.


Security patch for Rsync 2.6.2 2004-08-14
There is a path-sanitizing bug that affects daemon mode in all recent 'rsync' versions. For anyone running an 'rsync' daemon with chroot turned off while permitting the uploading of files, this bug can allow a carefully crafted filename for the --backup-dir option to cause 'rsync' to overwrite a file outside of the module's path. We applied the recommended patch.

For more information please refer to
  http://lists.samba.org/archive/rsync-announce/2004/000017.html


Maintenance upgrade to GnuPG 1.2.5 2004-08-14
Besides adding a number of new command line options this is mainly a bug fix release.


Security upgrade to SpamAssassin 2.64 2004-08-10
SpamAssassin is vulnerable to a Denial of Service attack when handling certain malformed messages. We fixed the problem by upgrading to revision 2.64 and restarted all running 'spamd' processes.

For more information please refer to
  http://marc.theaimsgroup.com/?l=spamassassin-announce&m=109168121628767&w=2


More security patches for png 1.2.5 2004-08-05
Several vulnerabilities exist in the 'libpng' library, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system. We applied the recommended patches.

For more information please refer to
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0597
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0598
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0599


Kernel patch 2004-08-03
Besides some other, less urgent problems we found and fixed a programming error in FreeBSD's VM system that can (and will) lead to a kernel panic due to a null pointer dereference under rare but not too unlikely circumstances. An official FreeBSD problem report submission is in the works. In order to activate the new UNIX kernel we had to reboot all of our servers. We apologize for the short service interruption (less than 10 minutes).


Another security fix for Pavuk 0.9.28 2004-07-28
Multiple vulnerabilities in Pavuk 0.9.28 are caused due to boundary errors within the digest authentication handler. This can be exploited via malicious digest authentication challenges with specially crafted nonce or realm values. We fixed the problem by applying the recommended patch.

For more information please refer to
  http://secunia.com/advisories/12152


Security upgrade to PHP 4.3.8 2004-07-15
Two security flaws have been found in PHP. One can be abused to execute arbitrary code on remote PHP servers, while the other may allow injection of malicious Javascript in the Internet Explorer and Safari browsers. In order to fix the problem we upgraded to revision 4.3.8 and restarted all running Apache processes.

Also, due to a change in PHP's configuration with regard to PDFLIB support we had to change the central 'php.ini' file. In order to ensure flawless operation for all server boxes we also updated private copies of this file.

For more information please refer to
  http://security.e-matters.de/advisories/112004.html
  http://security.e-matters.de/advisories/122004.html


Security upgrade to phpBB 2.0.9 2004-07-15
More security problems have been fixed in revision 2.0.9 of the popular phpBB2 discussion forum software. We installed this release now. Note that if you previously ran revision 2.0.8 there is no upgrade procedure necessary.


Maintenance upgrade to Centericq 4.10.0 2004-07-15
Just another round of bug fixes and IM protocol adjustments.


Maintenance upgrade to PostgreSQL 7.3.6 2004-07-14
A number of bugs in PostgreSQL have been fixed recently, so we upgraded to revision 7.3.6 now. This is a bug fix release, and there were no changes in functionality we know of.


New package: Snownews 2004-07-13
Snownews is a text mode RSS newsreader with plugin support for other feed formats. Its purpose is to keep track of updates to online magazines, news services, weblogs etc. in a time and resource efficient manner. Especially fans of Mutt, Slrn and Lynx may consider this a welcome addition.


Upgrade to Razor-agents 2.61 2004-07-12
In the ongoing spam vs. antispam arms race Razor-agents, a signature based spam detection mechanism embedded in SpamAssassin, has grown a new algorithm: Whiplash signatures. Whiplash signatures are based on canonical domain names present in URLs embedded in spam messages. We upgraded to revision 2.61, which supports the new feature, and restarted all running 'spamd' processes.


Security patch for png 1.2.5 2004-07-09
It has been discovered that the 'libpng' library does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers. We applied the recommended patch.

For more information please refer to
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1363


Kernel patch 2004-07-05
We decided to schedule a kernel update at this point because a programming error has been found in the filesystem code that, under rare but not too unlikely circumstances, can lead to a kernel panic due to a locking conflict. We fixed the problem by applying the recommended patch.

As usual, a load of other, less urgent fixes and improvements went into the new kernel as well, including faster and more efficient TCP retransmit algorithms like "Eifel detection" and "early retransmit" which can make a significant difference especially on slower or congested (dialup) links. In order to activate the new UNIX kernel we had to reboot all of our servers. We apologize for the short service interruption (less than 10 minutes).


Upgrade to CVS 1.11.17 2004-07-03
The latest stable CVS release (1.11.17) found its way into FreeBSD's STABLE branch now, so in light of all the recent security problems with CVS we upgraded swiftly to the new release.


Security fix for Pavuk 0.9.28 2004-07-02
A security audit revealed that Pavuk contains a buffer overflow bug potentially allowing an attacker to run arbitrary code. We fixed the problem by applying the recommended patch.


Upgrade to VIM 6.3.0 2004-07-02
This is a pure maintenance upgrade in order to keep our preinstalled version sufficiently recent.


Security patches for MC 4.6.0 2004-06-17
A number of buffer overflow vulnerabilities have been found since MC 4.6.0 was released. We fixed these problems by applying the recommended patches, some of which are just updates of fixes we had in place already.

For more information please refer to
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-1023
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0226
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0231
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0232


Webmail upgrade 2004-06-16
We upgraded to SquirrelMail 1.4.3a. This is a bug fix release that also resolves a number of XSS issues.


Security patch for Apache 1.3.31 2004-06-12
A buffer overflow in Apache's mod_proxy has been found that might be exploitable. We fixed the problem by applying the recommended patch. In order to activate the corrected version we restarted all running Apache instances.

For more information please refer to
  http://www.guninski.com/modproxy1.html


Maintenance upgrade to PHP 4.3.7 2004-06-12
This is another maintenance release with plenty of bug fixes. It addresses an input validation vulnerability, but this applies to the Windows platform, only.


Kernel security patch 2004-06-09
A programming error has been found that is resulting in a failure to verify that an attempt to manipulate routing tables originated from a non-jailed process. Jailed processes running with superuser privileges could modify host routing tables. This could result in a variety of consequences including packets being sent via an incorrect network interface and packets being discarded entirely.

We fixed the problem by applying the recommended patch. In order to activate the new UNIX kernel we had to reboot all of our servers. We apologize for the short service interruption (less than 10 minutes).

For more information please refer to
  ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:12.jailroute.asc


Habeas whitelist upgrade for SpamAssassin 2.63 2004-06-07
There has been widespread abuse lately of Habeas marks in email, which are normally supposed to help tell spam from ham. Habeas fixed the problem by switching from a blacklist-only mechanism to a combination of white- and blacklists. We installed the recommended patch now and restarted all running 'spamd' processes.

For more information please refer to
  http://www.habeas.com/pr16.html


Security fix for Gallery 1.3.4 2004-06-03
The Gallery developers found a major security issue with 'init.php', which allowed anybody to login as any user (including 'admin') with no password, by emulating that Gallery was embedded.

We fixed this by applying the recommended patch to both installed releases 1.3.3 and 1.3.4.


Security related kernel update 2004-05-28
Programming errors in the implementation of the msync(2) system call involving the MS_INVALIDATE operation lead to cache consistency problems between the virtual memory system and on-disk contents. In some situations, a user with read access to a file may be able to prevent changes to that file from being committed to disk.

We fixed the problem by applying the recommended patches. In order to activate the new UNIX kernel we had to reboot all of our servers. We apologize for the short service interruption (less than 10 minutes).

For more information please refer to
  ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:11.msync.asc


Upgrade to VIM 6.2.531 2004-05-28
This is a pure maintenance upgrade in order to keep our preinstalled version sufficiently recent.


Another security vulnerability in CVS 2004-05-19
Due to a programming error in code used to parse data received from the client, malformed data can cause a heap buffer to overflow, allowing the client to overwrite arbitrary portions of the server's memory. A malicious CVS client may run arbitrary code on the server at the privilege level of the CVS server software.

This programming error has a security impact only when using CVS in "pserver" mode. We fixed the problem by installing the recommended patch.

For more information please refer to
  http://security.e-matters.de/advisories/072004.html


Security upgrade to Apache 1.3.31 2004-05-17
Four security and DoS related bugs have been fixed in revision 1.3.31 of the Apache web server. In order to activate the new version we restarted all running Apache instances.

For more information please refer to
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0987
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0174
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0993


Maintenance upgrade to OpenSSH 3.8.1p1 2004-05-13
Just a number of minor bug fixes. There were no changes in functionality we know of.


New kernel feature 2004-05-11
Apart from a number of bug fixes and improvements that have accumulated over the last couple of weeks, we have raw IP socket support for server boxes in the kernel now, which means that commands like 'ping', 'traceroute' etc. work as expected. More sophisticated network tools like 'fping' and 'mtr' are in place too.

We implemented this feature in a secure way in that it is not possible to spoof the source IP address of packets or to access parts of the system through these sockets that are supposed to be off limits to server boxes (central firewall config etc.). In order to activate the new UNIX kernel we had to reboot all of our servers. We apologize for the short service interruption (less than 10 minutes).


Security fixes for phpBB 2.0.8a 2004-05-08
Two programming errors have surfaced in revision 2.0.8a of phpBB. We fixed them by installing the recommended patches.

For more information please refer to
  http://marc.theaimsgroup.com/?l=bugtraq&m=108239864203144
  http://www.securityfocus.com/archive/1/360931


Buffer overflow vulnerability in Exim 2004-05-06
All versions of Exim so far have been found to contain a programming error that can lead to a remotely exploitable stack-based buffer overflow. We fixed the problem with patches similar to those proposed in the security advisory and restarted all running Exim instances.

For more information please refer to
  http://www.guninski.com/exim1.html


Security flaw in png 1.2.5 2004-05-03
It has been discovered that the 'libpng' library would access memory that is out of bounds when creating an error message. The impact of this bug is not clear, but it could lead to a core dump in a program using 'libpng', or could result in a DoS condition in a daemon that uses 'libpng' to process PNG images. We applied the recommended patch.

For more information please refer to
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0421


Security upgrade to Rsync 2.6.2 2004-05-01
With 'rsync' in daemon mode, specially crafted paths could result in writing files outside of the module's "path" setting. Users not running a daemon, running a read-only daemon, or running a chrooted daemon are unaffected, though.

Actually, the security fix was in 2.6.1 already, but that release was botched and has been replaced by 2.6.2. Also, apart from other bug fixes, a number of improvements and optimizations have been introduced since revision 2.5.7.


Maintenance upgrade to mod_perl 1.29 2004-04-30