List of updates concerning program security

Can not find somewhere to post your question? Or want to test your signature, avator, links? Post it here. Thanks!

Moderators: Synology Inc, Honorary Moderator

List of updates concerning program security

Postby Franklin » Sat Apr 12, 2008 1:04 am

For April
Known vulnerabilities that should be fixed immediately.
1. Fix samba's security issue by applying security patches.
2. Fix the vulnerabilities of mt-daapd by upgrade it to 0.2.4.1

For May:
Upgrade packages and disable less secure functions.
1. Upgrade Apache, PHP, OpenSSL, rtorrent
2. Turn off HTTP Track, enhance SSL security level
3. Do not run LPR when there is no printer. Do not run LPR as root.

For Sep.
1. Disable PostgreSQL TCP/IP port. We need TCP/IP now for Download Redirector.
2. UPSd listens on remote port: We will add an option on UI to disable this.
This function is need for multiple DSes share 1 UPS.
3. All service running as root: We will review all service and run as root only when it is needed.

Will not implement:
1. Samba: NULL sessions are enabled on the remote host: We need this for guest login.
2. Samba: Shared files do not respect filesystem ACLs: We need this for share level access control
3. Running CGI as root. We need root permission to change system configuration.


All information is subject to change without notice.
**Franklin is not available**
**Please do not Private Message me for support questions; leave it on the forum so all members can learn. Thanks!**
Library ~ SynologyWiki ~ Synology FAQ ~ Compatibility Lists
Forum Links ~ Forum Policy ~ 3rd-party forums ~ Help us help you ~ Posting Images
Demo Links ~ DSM GUI ~ Photo Station
Downloads ~ Firmware Downloads ~ Beta Program
Support ~ Support Form ~ Submit Kernel ~ Synology eNews
User avatar
Franklin
Synology Inc
Synology Inc
 
Posts: 6772
Joined: Sat Oct 14, 2006 11:33 pm
Location: Washington, USA

Return to Others & Testing

Who is online

Users browsing this forum: No registered users and 1 guest