This is the old XigmaNAS forum in read only mode,
it will taken offline by the end of march 2021!



I like to aks Users and Admins to rewrite/take over important post from here into the new fresh main forum!
Its not possible for us to export from here and import it to the main forum!

PHP / POODLE Vulns

For "upgrading" from FreeNAS/NAS4Free Legacy to XigmaNAS and upgrading XigmaNAS to newer builds.
Forum rules
Set-Up GuideFAQsForum Rules
Post Reply
Con7undrum
NewUser
NewUser
Posts: 8
Joined: 08 Dec 2013 18:18
Status: Offline

PHP / POODLE Vulns

Post by Con7undrum »

Just ran a quick vuln scan and noticed that my NAS4Free (9.2.0.1 - Shigawire (revision 972)) has a few vulnerabilities. Namely, PHP and POODLE. I did a quick scan of the forums and saw a mention back in July about waiting for someone to update the PHP source files but nothing more. Are there any timelines for patching them? Does anyone know if there's a way to "upgrade" or patch the PHP binaries on a NAS4Free box?

TL;DR - NAS4Free has several PHP vulns and is vuln to POODLE. Are there ETAs for updates / patches?

User avatar
raulfg3
Site Admin
Site Admin
Posts: 4865
Joined: 22 Jun 2012 22:13
Location: Madrid (ESPAÑA)
Contact:
Status: Offline

Re: PHP / POODLE Vulns

Post by raulfg3 »

yes, PHP are patched on latest releases , you only need that this releases are compiled and uploaded or install from source to avoid vulneravilities.

http://sourceforge.net/p/nas4free/code/commit_browser
12.1.0.4 - Ingva (revision 7743) on SUPERMICRO X8SIL-F 8GB of ECC RAM, 11x3TB disk in 1 vdev = Vpool = 32TB Raw size , so 29TB usable size (I Have other NAS as Backup)

Wiki
Last changes

HP T510

Con7undrum
NewUser
NewUser
Posts: 8
Joined: 08 Dec 2013 18:18
Status: Offline

Re: PHP / POODLE Vulns

Post by Con7undrum »

Awesome! Ok, one more dumb question - is there a guide to compile / install the embedded version with the latest releases? Or instructions on how to install from source?

Con7undrum
NewUser
NewUser
Posts: 8
Joined: 08 Dec 2013 18:18
Status: Offline

Re: PHP / POODLE Vulns

Post by Con7undrum »


Con7undrum
NewUser
NewUser
Posts: 8
Joined: 08 Dec 2013 18:18
Status: Offline

Re: PHP / POODLE Vulns

Post by Con7undrum »

Apparently I was mistaken...the guide appears to not quite work the way I was expecting. Is there a more current or up-to-date guide / instruction set?

Post Reply

Return to “Upgrade XigmaNAS”