This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM Version 9.352-6 and 9.318-5 released (Do not install!!)

DO NOT INSTALL - THE UPDATES ARE FAULTY (Read this thread through!)

News

· Security Update
Remarks

· System will be rebooted
Bugfixes

36115 WebAdmin reflective XSS Vulnerability
36126 OpenSSL security update 1.0.1q



This thread was automatically locked due to age.
Parents
  • Hi all:

    regarding the Daily Executive Report - you are talking about the Daily Executive Report which is send by Email as HTML, right?

    The bad news is, at the least the patches for regarding the XSS should not be the source of this issue, since they are only targeting on POST requests in WebAdmin.

    The corresponding images in the Executive Report are directly integrated in the Email (by cid) and are therefore fully unrelated to the patches we released in this update.

    I had a couple of test runs on the same version and I cannot confirm this behavior, though I had been using a fresh install instead of an updated machine.

    Cheers,
    Sascha

    Cheers,

    Sascha Rudolph
    Senior Software Engineer, NSG

Reply
  • Hi all:

    regarding the Daily Executive Report - you are talking about the Daily Executive Report which is send by Email as HTML, right?

    The bad news is, at the least the patches for regarding the XSS should not be the source of this issue, since they are only targeting on POST requests in WebAdmin.

    The corresponding images in the Executive Report are directly integrated in the Email (by cid) and are therefore fully unrelated to the patches we released in this update.

    I had a couple of test runs on the same version and I cannot confirm this behavior, though I had been using a fresh install instead of an updated machine.

    Cheers,
    Sascha

    Cheers,

    Sascha Rudolph
    Senior Software Engineer, NSG

Children
  • also see no images in the daily pdf-report any more...

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • > The corresponding images in the Executive Report are directly integrated in the Email (by cid) and are
    > therefore fully unrelated to the patches we released in this update.

    9.351-3 HTML-Source in the Executive Report looks/looked like:
    img src="cid:cpuusage_daily_01234567890abcdefgh...."
    img src="cid:memswap_daily_01234567890abcdefg...."

    9.352-6 HTML-Source in the Executive Report looks like:
    img src="/var/rrd-nodataimages/cpuusage_nodata.png
    img src="/var/rrd-nodataimages/memswap_nodata.png