Collax Platform Server 5.0.2

Release Notes

Release date: 06/29/2009

Update Instructions

To install this update please follow these steps:

Procedure


Contents

Installation Notes

New in this Release

Problems Fixed in this Release


Installation 5.0.2

Auto Reboot

A new kernel is going to be installed and a reboot of the system is necessary. The output of the installation can be disrupted before the reboot is initialized.

Please note: Please wait, until all software packages are installed. The reboot of the system will then be initialized automatically and the server is going to be available after a few minutes.


New in Version 5.0.2

Hardware: Driver for 10GB Network Interface Cards

The driver for 10gigabit network interface cards will be implemented within kernel version 2.6.25.20. These driver support the following NICs: Chelsio 10Gb Ethernet, Chelsio Communications T3 10Gb Ethernet, Intel(R) 10GbE PCI Express, Intel(R) PRO/10GbE PCI-X, S2IO 10Gbe XFrame NIC, NetXen Multi port (1/10) Gigabit, Sun Neptune 10Gbit, Tehuti Networks 10G, Broadcom NetXtremeII 10Gb.

Add-on Software: New Version of Collax Virus Protection

The virus scanner Collax Virus Protection offers comprehensive antivirus protection for email services. Within this Collax system update the scanner is updated to the newest version.

The options for "Email disinfection", "Damaged Email" and "Alerts" are omitted from this update on. Emails can additionally be copied to quarantine (mail queue for hold mails) if they had been cleaned or before they shall be deleted.

Attention: Please start a manual pattern update by clicking the button "Get Updates" at the bottom of the form in Settings -> Filter -> Collax Virus Protection, Tab Mail. This update is necessary to start the services successfully.


Problems Fixed in Version 5.0.2

Security: Cryptography Toolkit OpenSSL

In the source code of the cryptography toolkit OpenSSL 0.9.8k security holes have been discovered. These holes will be closed within this Collax software update.

Assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2009-0590 CVE-2009-0591 CVE-2009-0789

Security: GNU TLS and SSL implementation

In the source code of GnuTLS security holes have been discovered. These holes will be closed within this Collax software update.

GnuTlS 2.6.6 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2008-4089 CVE-2009-1415 CVE-2009-1416 CVE-2009-1417

Security: Udev, Dynamic Device Management

In the source code of GnuTLS security holes have been discovered. These holes will be closed within this Collax software update.

A patch for udev 126 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2009-1185

Security: VPN IKE Daemon Pluto

In the source code of the IKE daemon Pluto security holes have been discovered. These holes will be closed within this Collax software update.

A patch for Pluto 2.4.9 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2009-0790

Security: GNU data type library glib2

In the source code of glib2 security holes have been discovered. These holes will be closed within this Collax software update.

A patch for glib2 2.18.2 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2008-4316

Security: Authentification library libsasl2

In the source code of system library libsasl2 security holes have been discovered. These holes will be closed within this Collax software update.

A patch for libsasl2 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2009-0688

Security: System library libfreetype

In the source code of system libraries libfreetyp security holes have been discovered. These holes will be closed within this Collax software update.

A patch for libfreetype is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2009-1416

Security: SquirrelMail Web Mail

In the source code of web mailer SquirrelMail security holes have been discovered. These holes will be closed within this Collax software update.

SquirrelMail 1.4.18 is going to be installed and fixes the assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2009-1578 CVE-2009-1579 CVE-2009-1580 CVE-2009-1581

Security: Samba, Windows SMB/CIFS Server for UNIX

In the source code of the Windows SMB/CIFS fileserver Samba security holes have been discovered. These holes will be closed within this Samba software patch for version 3.0.34.

Assigned Common Vulnerabilities and Exposures (CVE) numbers:

CVE-2009-1888