Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM Version 9.352-6 and 9.318-5 released (Do not install!!)

DO NOT INSTALL - THE UPDATES ARE FAULTY (Read this thread through!)

News

· Security Update
Remarks

· System will be rebooted
Bugfixes

36115 WebAdmin reflective XSS Vulnerability
36126 OpenSSL security update 1.0.1q



This thread was automatically locked due to age.
  • HEY SOPHOS!!!  WAKE UP!

     

    A whole month has gone by since you've delivered this crappy update and nothing happened. Unfortunately I had to install it to close some holes before a PCI scan happened. The scan was ok but now I have to live until the end of my life with a sluggy backend popping up these messages whenever I want to know what is eating up my bandwith?

     

    Hell what do I miss those Astaro days when the programmers and makers had an ear for problems like this and the forum was a platform for users AND programmers.

     

    We are running Astaro/Sophos since 2002 and the 2.0 software box is still lurking from a locker beside my desk (I love the graphics...).

    But the thousands of Euros we have spent some months ago for license renewing will be definitely the last ones.

  • for all without support:

    the fix for the graphics was posted here in a thread:

    login ssh with your loginuser
    change to root
    then these:

    cd /var/chroot-httpd/var/webadmin/var
    sudo -u wwwrun ln -s ../../log/reporting/images rrd-images

    this will fix the broken image situation.. but not the view of connection flow monitor!

    so fix this if you know how to login via ssh..

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • I have support (somebody used the term "lucky enough to have support"... Lucky? No, we PAY for support.

    RE the "fix" and the situation: Every one of my customers has a UTM. The "fix" is useless for production UTMs because it does not fix real time interaction with the UTM. This is less than a year after the last huge bug that broke reporting for almost a year. Wifi that was broken for a year (still sucks), concurrent connection bugs, memory leaks, httpd out of control, etc. etc.

    We are constantly faced with the same decision, patch vulnerabilities and deal with the inevitable breaking changes and bugs, or stay vulnerable.

    Do yourself a favor and come to the realization that Sophos does not give a rats ass about you or your customers or real world functionality. They care about marketing and demographics. Selling product (of any quality) to new customers and expanding their footprint is the goal. The folks in the head office don't care what a UTM is or does, they only care that its associated buzzwords enhance the appearance of their portfolio and the theoretical functionality wins useless industry awards. The sales guys are sell whatever corporate tells them to sell. Development's priority is putting out fires with huge customers and advancing the marketing directed roadmap. You and I, and our real world problems and the piles of bugs and broken modules are not part of the big picture. We are an afterthought that is relegated to tier 1 support where corporate only sees numbers from incident reports. If the incident reports are not high enough and the screams from BIG IT are not loud enough, then nothing gets done, regardless of the real world impact of the bug.

    These folks are clowns and this product has been a bug riddled mess from the moment Sophos took the reigns, and it is getting no better. I do not have a single customer that would ever buy a Sophos product again, under any circumstances.

    Alas, Sophos does not care about that either, because my customers are small single UTM shops, not school districts or medium/large enterprises that may buy hundreds of UTMs and/or thousands of seat licenses, etc.
  • 9.353-4 released (soft):

    community.sophos.com/.../74143

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v19 Architect

  • I could not agree more. We have been paying for "Premium Support", but no help here either. For example, I've been complaining more than 3 times now about L2TP/IPsec VPN giving the same IP (from its IP pool) to multiple clients at the same time. Last time I was told v9.351 would fix it. We're on v9.352 now, and the problem still persists. I'm not sure I even want to open a ticket again, because if I do, and even if I mention all the previous tickets related to the problem that have all the details in them, I will still have to start with Level 1 support from the beginning, and explain everything again. And then, they'll tell me to do stuff I've already done before, and which didn't help at all. They do not even bother to read the previous tickets to see what has already been done about fixing the issue. Level 1 support telling me something that Level2/3 support in a previous email has already rejected.

    I.AM.FRUSTRATED.NOW!

    Our UTM320 is coming EOL now, and the license is going to expire in a couple of months. I am in a process of selecting our future VPN solution right now. I have started looking into XG (well, why not, I want to be fair), but the UI is terrible (I strongly believe whoever designed UI for this forum, designed the UI for XG as well). It's even worse than UTM9. And the latest technologies? Well, IKEv2 is still nowhere to find. And I'm probably not even using UTM/XG to its full extent as many of you guys probably do. All I need is VPN, and maybe web proxy. I was going to give Sophos a chance and I started evaluating their products first, but I'm not going to hold my breath. If anyone has any suggestions about a good enterprise level VPN solution, I'm all ears. We're most likely not going to purchase XG or renew UTM. And if we do, then it means other vendors suck even more than Sophos.

    Sorry about typos, I'm seriously upset about all this.

  • 9.353-4 on the FTP site ->>> community.sophos.com/.../74143

    News:
     Maintenance Update
    
    Bugfixes:
     Fix [29945]: SPX password notification mails have no header and footer customization
     Fix [35236]: rsync does not sync up2date/pattern packages due to corrupted rsyncd.conf
     Fix [35300]: Interface was deleted through backup restore
     Fix [35368]: HTTP Proxy fails to lookup correct backend group intermittently
     Fix [35511]: Maildrop lock will not removed by pop3proxy
     Fix [35521]: Support Access user cannot be enabled if complex passwords & non-alphanumeric character required
     Fix [35645]: FTP Proxy: frox segfault still occurs after udpate to 9.314
     Fix [35683]: Update kernel to 3.12.48
     Fix [35704]: WAN Failover on RED50 with static IP addresses not successful
     Fix [35739]: SPX Encryption works only if the customer uses "senderspec" as option
     Fix [35750]: SMTP Proxy dies every two hours when using SPX
     Fix [35755]: User Portal: Login not possible - "Authentication system error"
     Fix [35766]: Certificate with Netscape Cert Type: SSL Client not usable for S/MIME encryption
     Fix [35787]: SG1xxW: middleware errors + changing txpower not working
     Fix [35797]: dynamic mac filter changes not working
     Fix [35799]: Corrupted rpmdb - check and repair from 33545 doesn't work
     Fix [35810]: Web Proxy unable to start following update to 9.350
     Fix [35816]: spx-auth dies without any log entry
     Fix [35923]: HTTP Proxy: fix of memory leaks
     Fix [35928]: Windows devices randomly showing up as Linux device=3 in httpproxy with device authentication
     Fix [35970]: Remote access reporting is incorrect
     Fix [35974]: Printable config doesn't show content of WebAdmin user preferences > shortcuts in Confd format
     Fix [35978]: Update ntp to 4.2.8
     Fix [35979]: HTTP Proxy does not provide full certificate chain when using custom cert for enduser pages
     Fix [35980]: Proceed button for a forbidden file extension change the signature of a https request
     Fix [35985]: Executive Report: VPN client 'duration' counted incorrectly if users logged > 1 day
     Fix [35994]: MAC filter list with more than 700 entries doesn't get updated on change
     Fix [35999]: FTP over HTTP: directory listing uses wrong paths
     Fix [36008]: SPX registration mails mess up exim header sporadically
     Fix [36012]: No "Server Hello" is send by WebProxy from the UTM to the client
     Fix [36013]: Installation of first package failed during Up2Date (db_verify?)
     Fix [36019]: IP range objects in allowed relays will not insert in the exim configuration
     Fix [36065]: Webadmin triggers L2TP over IPsec PSK change if "&" is used in PSK
     Fix [36086]: Executive Report: Wrong count of ssh logins in summary
     Fix [36171]: Flow Monitor broken since the XSS patches
     Fix [36221]: After update to version 9.317/9.351 SMTP messages stop being processed (without any notifications/errors in log)

    Regards Simon

    UTM - 9.411-3 | Intel(R) Core(TM) i5-3550 CPU @ 3.30GHz
    8GB Memory | Samsung EVO 850 120GB SDD | Intel GB Ethernet x3

  • Once I'm able to download this on my UTM, is it possible to go from 9.351-3 directly to new build and bypass the one that is waiting on the UTM?
  • short and simple: NO

    you have to install 9.352006 first to go the way to 9.353004..

    look at the name of the update file u2d-sys-9.352006-353004.tgz.gpg

    read it like this: from-Version_to-Version

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • You cannot bypass it, but if you upload all available updates up to 9.352006-353004 and click on "Update to latest" than it will silently update to the latest available update version. You don't have to fiddle around with the faulty 352, it will just be a part of the update path.