Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM Version 9.352-6 and 9.318-5 released (Do not install!!)

DO NOT INSTALL - THE UPDATES ARE FAULTY (Read this thread through!)

News

· Security Update
Remarks

· System will be rebooted
Bugfixes

36115 WebAdmin reflective XSS Vulnerability
36126 OpenSSL security update 1.0.1q



This thread was automatically locked due to age.
Parents Reply
  • Considering the XSS vulnerability discussed here www.heise.de/.../Sicherheitspaket-UTM-von-Sophos-loechrig-3044717.html you would have thought that sophos would patch this pretty quickly. Not sure how the vulnerability is exploited, but I would make sure that my webadmin is not listening on ANY or INTERNET facing interfaces just to be safe.
    First a half baked update and now I am assuming its holiday season at sophos HQ. Releasing a patch obtainable via support only was great for paying customers but sophos will get just as much of a black eye if someone's home installation gets hacked due to the XSS exploit.
Children
No Data