Just ran a quick vuln scan and noticed that my NAS4Free (9.2.0.1 - Shigawire (revision 972)) has a few vulnerabilities. Namely, PHP and POODLE. I did a quick scan of the forums and saw a mention back in July about waiting for someone to update the PHP source files but nothing more. Are there any timelines for patching them? Does anyone know if there's a way to "upgrade" or patch the PHP binaries on a NAS4Free box?
TL;DR - NAS4Free has several PHP vulns and is vuln to POODLE. Are there ETAs for updates / patches?
This is the old XigmaNAS forum in read only mode,
it will taken offline by the end of march 2021!
I like to aks Users and Admins to rewrite/take over important post from here into the new fresh main forum!
Its not possible for us to export from here and import it to the main forum!
it will taken offline by the end of march 2021!
I like to aks Users and Admins to rewrite/take over important post from here into the new fresh main forum!
Its not possible for us to export from here and import it to the main forum!
PHP / POODLE Vulns
- raulfg3
- Site Admin

- Posts: 4865
- Joined: 22 Jun 2012 22:13
- Location: Madrid (ESPAÑA)
- Contact:
- Status: Offline
Re: PHP / POODLE Vulns
yes, PHP are patched on latest releases , you only need that this releases are compiled and uploaded or install from source to avoid vulneravilities.
http://sourceforge.net/p/nas4free/code/commit_browser
http://sourceforge.net/p/nas4free/code/commit_browser
12.1.0.4 - Ingva (revision 7743) on SUPERMICRO X8SIL-F 8GB of ECC RAM, 11x3TB disk in 1 vdev = Vpool = 32TB Raw size , so 29TB usable size (I Have other NAS as Backup)
Wiki
Last changes
HP T510
Wiki
Last changes
HP T510
-
Con7undrum
- NewUser

- Posts: 8
- Joined: 08 Dec 2013 18:18
- Status: Offline
Re: PHP / POODLE Vulns
Awesome! Ok, one more dumb question - is there a guide to compile / install the embedded version with the latest releases? Or instructions on how to install from source?
-
Con7undrum
- NewUser

- Posts: 8
- Joined: 08 Dec 2013 18:18
- Status: Offline
-
Con7undrum
- NewUser

- Posts: 8
- Joined: 08 Dec 2013 18:18
- Status: Offline
Re: PHP / POODLE Vulns
Apparently I was mistaken...the guide appears to not quite work the way I was expecting. Is there a more current or up-to-date guide / instruction set?