The symlink race condition vulnerability

May 15, 2019
24
2
3
California
cPanel Access Level
Website Owner
I'm running Webhost manager on Ubuntu 20.4 (cpanel's supported version) but I only have the "BlueHost version" to patch this vulnerability. Cloudlinux has several methods, Is there a fix on the way from cPanel for this issue?
 
May 15, 2019
24
2
3
California
cPanel Access Level
Website Owner
This is what it says:

The Bluehost patch improves Apache’s ability to detect a race condition. The Bluehost patch modifies Apache and the Apache Portable Runtime (APR) library so that Apache cannot access certain files.

It's my only option to patch it in Web Host Manager. But it says it's not optimal for patching it.
 
May 15, 2019
24
2
3
California
cPanel Access Level
Website Owner
Security Advisor says this:
Apache Symlink Protection: the Bluehost provided Apache patch is in effect
It appears that the Bluehost provided Apache patch is being used to provide symlink protection. This is less than optimal.
 

cPRex

Jurassic Moderator
Staff member
Oct 19, 2014
17,470
2,843
363
cPanel Access Level
Root Administrator
Hey there! I see you also posted here:


Since this is related to Apache, it's really not up to Ubuntu to decide how to handle this.

For an Ubuntu system, the BlueHost patch is the only option currently available. If you feel you need additional protection, it might be worth switching to a Redhat-based operating system. Since the other more exhaustive options are kernel-based, they just aren't available for Ubuntu.
 

agnelp

Registered
Dec 31, 2021
3
0
1
united states
cPanel Access Level
Root Administrator
Hey there! I see you also posted here:


Since this is related to Apache, it's really not up to Ubuntu to decide how to handle this.

For an Ubuntu system, the BlueHost patch is the only option currently available. If you feel you need additional protection, it might be worth switching to a Redhat-based operating system. Since the other more exhaustive options are kernel-based, they just aren't available for Ubuntu.
Hi! we been using Alma Linux until Redhat change the game, we cannot can go back and forward with customers, this is a real life not a joke, we been dealing with rpm because cPanel, after that no thanks, so finally get close to our matrix for more than 20yrs (debian) with ubuntu + cPanel but i fell like nothing work on the same way, is a long way now!

same problem here, cagefs, cloudlinux and litespeed do not work in the same way, I suppose we have to wait even if we pay for the licenses of each of the mentioned technologies, but our clients will wait? guys you will have to do something quickly especially on the subject compatibility, security and stability

Thank's