Tools

Serv-U 15.4.2 Hotfix 1 Release Notes

This article provides an overview of Serv-U 15.4.2 Hotfix 1, released on May 2, 2024, and provides instructions for installing and uninstalling the hotfix.

First published date

5/2/2024 4:17 PM

Last published date

6/2/2025 9:52 PM

Overview

This hotfix requires that Serv-U 15.4.2 be installed. It addresses the following issues: 

  • Inconsistent HTTP session authentication when the password used contains special characters. 

  • Group administrators can create access to restricted file system directories. 

  • Sporadic failure to establish SSH connection under specific network conditions. 

  • New web client corrupts the user’s password when the user’s password is changed. 

SolarWinds CVEs 

SolarWinds would like to thank our Security Researchers below for reporting on the issue in a responsible manner and working with our security, product, and engineering teams to fix the vulnerability. 

CVE-ID 

Vulnerability Title 

Description 

Severity 

Credit

CVE-2024-28072 

SolarWinds Serv-U Arbitrary File Overwrite Vulnerability 

A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. 

5.7 Medium 

Alexander Skovsende at the Institut For Cyber Risk 

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Resolution

Environment: 

Serv-U 15.4.2

Requirements

This hotfix is suitable for both Windows and Linux OSs, 32-bit and 64-bit. It requires Serv-U 15.4.2. 

Installation instructions   

This hotfix contains the following files and folders required to upgrade your installation:  

Windows OS: 

  • Serv-U.exe 

  • Serv-U-Tray.exe 

  • Serv-U.dll 

  • Serv-U-RES.dll 

  • RhinoNET.dll 

  • RhinoRES.dll 

  • Client\Common\Scripts\functions.js 

  • Client\WebClientNew 

Linux OS:

  • Serv-U 

  • Client/Common/Scripts/functions.js 

  • Client/WebClientNew 

In the following procedures, the default installation directory <Serv-U-InstallDir> is:  

Windows OS 

  • C:\Program Files\RhinoSoft\Serv-U 

Linux OS: 

  • /usr/local/Serv-U 

Install the hotfix 

  1. Shut down all running Serv-U processes. 

  1. Right-click the tray icon and select Stop Serv-U. 

  1. Right-click the tray icon and select Exit Tray. 

  1. Back up the following files and folders: 

  • In Windows OS: 

    • <Serv-U-InstallDir>\Serv-U.exe 
    • <Serv-U-InstallDir>\Serv-U-Tray.exe 
    • <Serv-U-InstallDir>\Serv-U.dll 
    • <Serv-U-InstallDir>\Serv-U-RES.dll 
    • <Serv-U-InstallDir>\RhinoNET.dll 
    • <Serv-U-InstallDir>\RhinoRES.dll 
    • <Serv-U-InstallDir>\Client\Common\Scripts\functions.js 
    • <Serv-U-InstallDir>\Client\WebClientNew\ 
  • In Linux OS: 

    • <Serv-U-InstallDir>/Serv-U 
    • <Serv-U-InstallDir>/Client/Common/Scripts/functions.js 
    • <Serv-U-InstallDir>/Client/WebClientNew/ 
  1. Extract the hotfix archive to a temporary location. 

  1. Open the folder for the platform on which Serv-U is installed. 
    For example, open the Linux/64-bit folder if Serv-U is installed on a 64-bit version of Linux. 

  1. On Linux, modify the permissions of the file by executing the following command:  
    chmod u+xs Serv-U 

  1. Copy the contents of this folder to your Serv-U installation directory. 

  1. Start the Serv-U Tray application. 

  1. Right-click the Serv-U Tray icon and select Start Serv-U. 
    The hotfix is installed. 

Result 
The issues listed at the top of the page are resolved.  

Uninstall the hotfix

  1. Shut down all running Serv-U processes. 

  1. Right-click the tray icon and select Stop Serv-U. 

  1. Right-click the tray icon and select Exit Tray. 

  1. Replace the following files and folders with the ones you backed up during installation: 

  • In Windows OS: 

    • <Serv-U-InstallDir>\Serv-U.exe 
    • <Serv-U-InstallDir>\Serv-U-Tray.exe 
    • <Serv-U-InstallDir>\Serv-U.dll 
    • <Serv-U-InstallDir>\Serv-U-RES.dll 
    • <Serv-U-InstallDir>\RhinoNET.dll 
    • <Serv-U-InstallDir>\RhinoRES.dll 
    • <Serv-U-InstallDir>\Client\Common\Scripts\functions.js 
    • <Serv-U-InstallDir>\Client\WebClientNew\ 
  • In Linux OS: 

    • <Serv-U-InstallDir>/Serv-U 
    • <Serv-U-InstallDir>/Client/Common/Scripts/functions.js 
    • <Serv-U-InstallDir>/Client/WebClientNew/ 
  1. Start the Serv-U Tray application. 

  1. Right-click the Serv-U application. 
    The hotfix is uninstalled. 

For more information, contact Technical Support at  https://serv-u.com/support.