Hi,
getting close to v17b release. 5.7 MR7 was a suggested release before V17b was released?
Ian
This thread was automatically locked due to age.
HI
MR7 Released .
BR
Vishvas
HI
MR7 Released .
BR
Vishvas
Hi All,
we've finished SFOS v16.05.7 MR7. This release is available from within your device for all SFOS v16.05 installations.
The release is available to all SFOS version via MySophos portal.
Issues Resolved
Hi Aditya Patel these are some serious vulnerabilities that were patched upstream long time ago. Does this mean that all the previous versions of XG are vulnerable? Also, the sql injections, are they low priority where only an admin with login credentials can inject code or anyone from LAN or WAN(if enabled) can inject code. Dropbear CVEs are months old and dirty cow??? XG is still vulnerable to dirty cow???? I will post the same question under the release notes because this is scary
NC-19720 [API] SQL Injection: Application filter add type
NC-19721 [API] SQL Injection: Proxy port config
NC-19775 [API] SQL Injection: User add/edit
NC-19558 [Base System] Add kernel patch for 'Stack Clash'CVE-2017-1000364
NC-19920 [Base System] Several vulnerabilitiy patches for Dropbear (CVE-2016-7409, CVE-2016-7408, CVE-2016-7407, CVE-2016-7406)
NC-21237 [Base System] Linux Kernel vulnerability "Dirty Cow" (CVE-2016-5195)
NC-19716 [UI] SQL Injection: Current Activities
NC-19753 [UI] SQL Injection: filter function
NC-19540 [WAF] WAF - Fix CVE-2017-7679: mod_mime buffer overread
NC-19717 [WAF] SQL injection: IPS backend server add
NC-19718 [Web] SQL Injection: Proxy file type add
NC-20787 [Web] Proxying is allowed through port 8090
NC-19719 [Wireless] Blind code execution: Access point edit
Thanks for looking into this.
after applying SFOS v16.05.7 MR7 our mail server stop receiving mails with the message
[SMTP Status] 421 4.3.2 The maximum number of concurrent connections has exceeded a limit, closing transmission channel
[SMTP Status] 451 4.7.0 Timeout waiting for client input
reverting back to MR6 fixed the issue.
also for me after apply SFOS 16.05.7 MR7 our mail server stop receiving mail.
I have noticed also that IPS patterns fails to update.
So i revert back to MR6.
The Device acts as a Transparent Proxy.