Server Software Notification List Message: 03-14-2007
Note: On 03/01/2007, all platforms were updated to address recent changes in Daylight
Savings Time in the United States and Canada. These changes should not require any action for Linux MPS/VPS or Signature accounts.
FreeBSD MPS/VPS v1, v2, and v3 and Solaris MPS/VPS v1 may be affected by this change. Refer to reseller announcements regarding this
update and the following page for further information and instructions:
The following updates will be completed 03/14/2007 on all servers:
Linux MPS/VPS
- Apache
- The default Apache Web server configuration file will be updated to include a Directory tag configuration for /home/*/www for
new accounts. For current configurations, check the /www/conf/httpd.conf file and add the following tags if not present:
<directory "/home/*/www">
Options Indexes MultiViews SymLinksIfOwnerMatch IncludesNoExec
AllowOverride All
Order allow,deny
Allow from all
</directory>
- vadduser
- The vadduser command-line utility will be updated to correctly create the Mail directory for users when CPX is installed. To
check for any users affected, verify the Mail directory exists in the user's home directory.
The vadduser utility will also be updated to address problems with offering users large quotas. No action needed.
- Time Zone
- A new vinstall to interactively set the time zone of the server will be added to the system. This will allow you to
interactively set the time zone on your virtual private server, based on a major city in the desired time zone. If you want to
take advantage of this update, connect to your server through SSH and execute the following command from the prompt:
# vinstall timezone
- Mailman
- The vinstall for Mailman, the GNU Mailing List Manager, will be updated to include the setting of the administrative passwords.
This update affects the vinstall only. No action needed.
- ClamAV
- The vinstall for ClamAV, a GPL virus scanner, will be updated with improved text describing the ClamAV milter option. This
update affects the vinstall only. No action needed.
- yum
- The yum software package manager will be updated to use official Red Hat repositories in place of local repositories. Also,
the ISO repository will be removed. No action needed.
- sinfo
- The sinfo command-line utility has been updated to correctly display multiple IP addresses. No action needed.
- Perl Modules
- The proprietary Install Perl module version 1.1 will be added to the system. No action needed.
FreeBSD MPS/VPS v3
- vaddhost
- The proprietary vaddhost command-line utility will be updated to ask for the IP address to associate with a subhost when
adding a subhost to the server. The update affects vaddhost only. No action needed.
- vaddcert
- A new proprietary command-line utility, vaddcert, will be added to the system. This utility assists with installing certificates
for different domains. To use vaddcert, connect to your serve through SSH and execute the following from the command prompt:
# vaddcert
- SquirrelMail
- The vinstall for the SquirrelMail Webmail package will be updated to install version 1.4.9a. The vinstall will also be updated
to allow for installation per subhost domain and include more information about the installation. The vuninstall for SquirrelMail
will also be updated to address issues with PHP. To take advantage of this update, make a backup of your current configuration,
uninstall the application, then connect to your server through SSH and execute the following from the command prompt:
# vinstall squirrelmail
The vuninstall for the SquirrelMail Webmail package will be updated to address issues with different versions. This update
affects the vuninstall only. No action needed.
- PostgreSQL
- The vinstall for the PostgreSQL database management system will be updated to install version 8.1.6. This version addresses
issues with tar-format backups, race conditions, deadlock errors, large hash indexes, and several other bugs and improvements.
The PostgreSQL PHP extension will also be recompiled. More information about version 8.1.6 can be found here:
http://www.postgresql.org/docs/8.1/static/release-8-1-6.html
To install PostgreSQL, connect to your server through SSH and run the following from the command prompt:
# vinstall postgresql
Follow the onscreen instructions to complete the installation.
Note: To upgrade existing installations, make a backup of all databases, shutdown
PostgreSQL, and uninstall the current version before running "vinstall postgresql" (above). For considerations in upgrading
between versions of PostgreSQL, including avoiding data loss, see:
http://www.postgresql.org/docs/8.1/static/install-upgrading.html
- GPG
- GPG (GNU Privacy Guard or GnuPG) will be updated to version 2.0.2. This version brings the utility to the most current
FreeBSD version. More information about version 2.0.2 can be found here:
http://www.freshports.org/commit.php?category=security&port=gnupg
No action needed.
- vadduser
- The vadduser command-line utility will be updated to correctly create the Mail directory for users when CPX is installed.
To check for any users affected, verify the Mail directory exists in the user's home directory.
- Time Zone
- The timezone vinstall utility will be updated to address the recent changes in Daylight Savings Time. This is an update to
the vinstall only. Refer to the note in this Notification and reseller announcements for considerations and actions needed.
- Mailman
- The vinstall for Mailman, the GNU Mailing List Manager, will be updated to include the setting of the administrative passwords.
This update affects the vinstall only. No action needed.
- ClamAV
- The vinstall for ClamAV, a GPL virus scanner, will be updated with improved text describing the ClamAV milter option. This
update affects the vinstall only. No action needed.
- Portupgrade
- The Portupgrade FreeBSD ports/packages administration and management tool suite will be updated to version 2.2.2_4,2. This
version brings the utility to the most current FreeBSD version. More information about version 2.2.2_4,2 can be found here:
http://www.freshports.org/commit.php?category=ports-mgmt&port=portupgrade
No action needed.
- UnZip
- The Info-ZIP UnZip archive extraction utility will be updated to version 5.52_3. This version brings the utility to the most
current FreeBSD version and addresses issues with files over 2 GB. More information about version 5.52_3 can be found here:
http://www.freshports.org/commit.php?category=archivers&port=unzip
No action needed.
- Libgmp
- Libgmp, a free library for arbitrary precision arithmetic, will be updated to version 4.2.1_2. This version brings the utility
to the most current FreeBSD version and addresses issues with the C++ wrapper and mpz_set_d. More information about version 4.2.1_2
can be found here:
http://www.freshports.org/commit.php?category=math&port=libgmp4
No action needed.
- UnRAR
- The unRAR archive utility, part of RAR: Roshal ARchive data compression software, will be updated to version 3.70.b3,4. This
version brings the utility to the most current FreeBSD version and addresses issues with the Chinese language. More information
about version 3.70.b3,4 can be found at these pages:
No action needed.
- JasPer
- The JasPer implementation of the JPEG-2000 standard specification will be updated to version 1.900.1. This version brings the
utility to the most current FreeBSD version. More information about the changes in version 1.900.1 can be found here:
http://www.freshports.org/commit.php?category=graphics&port=jasper
No action needed.
- IP-Country
- The IP-Country Perl module will be updated to version 2.23. This version brings the utility to the most current FreeBSD version
and addresses issues with lowercase country codes. More information about version 2.23 can be found here:
http://search.cpan.org/src/NWETTERS/IP-Country-2.23/CHANGES
No action needed.
- SQLite
- The SQLite database engine will be updated to version 3.3.12. This version addresses issues with assertion faults, syntactic
changes, and other issues. More information about version 3.3.12 can be found at these pages:
http://www.sqlite.org/changes.html#version_3_3_12
No action needed.
- Libgcrypt
- The Libgcrypt cryptographic library will be updated to version 1.2.4. This version brings the utility to the most current FreeBSD
version. More information about version 1.2.4 can be found here:
http://www.freshports.org/commit.php?category=security&port=libgcrypt
No action needed.
- Perl 5 Net Class
- The Perl 5 Net class of modules will be updated to version 1.20_1,1. This version brings the class to the most current FreeBSD
version and address UTF-8 issues. More information about version 1.20_1,1 can be found here:
http://www.freshports.org/commit.php?category=net&port=p5-Net
No action needed.
- Math::BigInt
- The Math::BigInt Perl module will be updated to version 1.79. This version brings the module to the most current FreeBSD version.
More information about version 1.79 can be found here:
http://search.cpan.org/src/TELS/Math-BigInt-1.79/CHANGES
No action needed.
- XML::SAX
- The XML::SAX Perl module will be updated to version 0.15. This version brings the module to the most current FreeBSD version and
addresses issues with attribute values and warnings. More information about version 0.15 can be found here:
http://search.cpan.org/src/GRANTM/XML-SAX-0.15/Changes
No action needed.
- Qt
- The Qt C++ toolkit will be updated to version 3.3.7. This version brings the utility to the most current FreeBSD version. More
information about version 3.3.7 can be found at these pages:
No action needed.
- Pinentry-qt
- The QT-based pinentry dialog will be updated to version 0.7.2_5. This version brings the utility to the most current FreeBSD
version. More information about pinentry-qt can be found here:
http://www.freshports.org/commit.php?category=x11-toolkits&port=qt33
No action needed.
- libmng
- The MNG (Multiple-image Network Graphics) library will be updated to version 1.0.9. This version address issues with hash functions,
shlib filtering, and categories. More information about version 1.0.9 can be found at these pages:
No action needed.
- GnuTLS
- The GnuTLS portable ANSI C-based library will be updated to version 1.6.1_1. This version brings the utility to the most current
FreeBSD version. More information about version 1.6.1_1 can be found here:
http://www.freshports.org/commit.php?category=security&port=gnutls
No action needed.
- NAS
- The NAS (Network Audio System) utility version 1.8 will be added to the system to fulfill dependency needs. More information
about NAS can be found here:
No action needed.
FreeBSD MPS/VPS v2:
- Backroom
- The Backroom Order Wizard will be updated to include an option to install the Sendmail RBL (real-time blackhole list)
subscription utility at ordering time. No action needed.
- PHP
- The vinstall for the PHP: Hypertext Preprocessor scripting language will be updated to install version 4.4.5. This version
brings the software to the most current 4.x version and addresses several issues, some dealing with security and vulnerabilities,
including:
- Fixed possible safe_mode & open_basedir bypasses inside the session extension.
- Fixed possible overflows and stack corruptions in the session extension.
- Fixed an underflow inside the internal sapi_header_op() function.
- Fixed possible overflows inside zip & imap extensions.
- Fixed a possible overflow in the str_replace() function.
- Fixed a possible information disclosure inside the wddx extension.
- Fixed a possible string format vulnerability in *print() functions on 64 bit systems.
- Fixed a possible buffer overflow inside ibase_{delete,add,modify}_user() function.
- Fixed a string format vulnerability inside the odbc_result_all() function.
- Fixed a possible buffer overflow inside mail() function on Windows.
More information about changes in version 4.4.5 can be found at these pages:
Note that some extensions that used to be included with the installation are now external shared extensions that can be chosen
through a toggle-style prompt during the vinstall process.
To install PHP or upgrade existing installations to the new version, connect to your server through SSH and execute the following
command from the prompt:
# vinstall php4
- vadduser
- The vadduser command-line utility will be updated to correctly create the Mail directory for users when CPX is installed.
To check for any users affected, verify the Mail directory exists in the user's home directory.
- Time Zone
- The timezone vinstall utility will be updated to address the recent changes in Daylight Savings Time. This is an update to
the vinstall only. Refer to the note in this Notification and reseller announcements for considerations and actions needed.
- vuninstall
- The vuninstall for mysql4 will be removed from the system. This update affects the vuninstall only. No action needed.
- Mailman
- The vinstall for Mailman, the GNU Mailing List Manager, will be updated to include the setting of the administrative passwords.
This update affects the vinstall only. No action needed.
- ClamAV
- The vinstall for ClamAV, a GPL virus scanner, will be updated with improved text describing the ClamAV milter option. This
update affects the vinstall only. No action needed.
- Squirrelmail
- The vinstall for the SquirrelMail Webmail package will be updated to install version 1.4.9a. The vinstall will also be updated
to allow for installation per subhost domain and include more information about the installation. The vuninstall for SquirrelMail
will also be updated to address issues with PHP. To take advantage of this update, make a backup of your current configuration,
uninstall the application, then connect to your server through SSH and execute the following from the command prompt:
# vinstall squirrelmail
- GPG
- GPG (GNU Privacy Guard or GnuPG) will be updated to version 1.4.6_3. This version brings the utility to the most current
FreeBSD version for GPG 1.x and addresses issues with symlinks (symbolic links) and directory information. More information
about version 1.4.6_3 can be found here:
http://www.freshports.org/commit.php?category=security&port=gnupg1
No action needed.
- Portupgrade
- The index.db file used by the Portupgrade FreeBSD ports/packages administration and management tool suite will be updated to
address package corruption issues and to reflect current packages and dependencies. No action needed.
- Libgmp
- Libgmp, a free library for arbitrary precision arithmetic, will be updated to version 4.2.1_2. This version brings the utility
to the most current FreeBSD version and addresses issues with the C++ wrapper and mpz_set_d. More information about version 4.2.1_2
can be found here:
http://www.freshports.org/commit.php?category=math&port=libgmp4
No action needed.
- UnZip
- The Info-ZIP UnZip archive extraction utility will be updated to version 5.52_3. This version brings the utility to the most
current FreeBSD version and addresses issues with files over 2 GB. More information about version 5.52_3 can be found here:
http://www.freshports.org/commit.php?category=archivers&port=unzip
No action needed.
- JasPer
- The JasPer implementation of the JPEG-2000 standard specification will be updated to version 1.900.1. This version brings the
utility to the most current FreeBSD version. More information about the changes in version 1.900.1 can be found here:
http://www.freshports.org/commit.php?category=graphics&port=jasper
No action needed.
- UnRAR
- The unRAR archive utility, part of RAR: Roshal ARchive data compression software, will be updated to version 3.70.b3,4. This
version brings the utility to the most current FreeBSD version and addresses issues with the Chinese language. More information
about version 3.70.b3,4 can be found at these pages:
No action needed.
- libedit
- The libedit command-line editing utility version will be updated to version 2.6.10. This version is the most current FreeBSD
version. More information about version 2.6.10 can be found here:
http://www.freshports.org/commit.php?category=devel&port=libedit
No action needed.
Signature
- Control Panel
- The Control Panel will be updated to address issues with the following:
- Correct permissions for subusers who have been granted access to portions of the Web site
- Allow email messages with both Japanese and Chinese characters in Webmail
- Show the version number of the Control Panel in the Web interface
- Support for Japanese in WordPress through the Web interface
- Display and handling of HTML mail messages
- Problems with UTF-8-encoded mail messages
- qmail
- The qmail mail server will be updated to support TLS (Transport Layer Security) and SMTP AUTH (SMTP Authentication) for port
587 only. If you use port 25 to send email, no action needed.
For those using port 587 to send email you may need to update the configuration of your email client. If your email client is
configured to use TLS when available, make sure the mail server address your client is connecting to matches the shared
certificate provided with the account.
For those using port 587 you can now configure your email client to use (or "send") authentication when sending email. This
configuration is different for each kind of email client. Refer to your client help and documentation for further information
about client configuration and settings.
Note: This
notification could include technical inaccuracies or typographical errors. Changes can be made to the information herein;
these changes will be distributed in new notifications. AlpineWeb might make improvements and/or changes in the product(s)
and/or the program(s) described in this publication at any time.
|
|