Tools
Serv-U 15.4.2 Hotfix 1 Release Notes
This article provides an overview of Serv-U 15.4.2 Hotfix 1, released on May 2, 2024, and provides instructions for installing and uninstalling the hotfix.
First published date
Last published date
Overview
This hotfix requires that Serv-U 15.4.2 be installed. It addresses the following issues:
-
Inconsistent HTTP session authentication when the password used contains special characters.
-
Group administrators can create access to restricted file system directories.
-
Sporadic failure to establish SSH connection under specific network conditions.
-
New web client corrupts the user’s password when the user’s password is changed.
SolarWinds CVEs
SolarWinds would like to thank our Security Researchers below for reporting on the issue in a responsible manner and working with our security, product, and engineering teams to fix the vulnerability.
|
CVE-ID |
Vulnerability Title |
Description |
Severity | Credit |
|
CVE-2024-28072 |
SolarWinds Serv-U Arbitrary File Overwrite Vulnerability |
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. |
5.7 Medium | Alexander Skovsende at the Institut For Cyber Risk |
Product section
Resolution
Environment:
Serv-U 15.4.2
Requirements
This hotfix is suitable for both Windows and Linux OSs, 32-bit and 64-bit. It requires Serv-U 15.4.2.
Installation instructions
This hotfix contains the following files and folders required to upgrade your installation:
Windows OS:
-
Serv-U.exe
-
Serv-U-Tray.exe
-
Serv-U.dll
-
Serv-U-RES.dll
-
RhinoNET.dll
-
RhinoRES.dll
-
Client\Common\Scripts\functions.js
-
Client\WebClientNew
Linux OS:
-
Serv-U
-
Client/Common/Scripts/functions.js
-
Client/WebClientNew
In the following procedures, the default installation directory <Serv-U-InstallDir> is:
Windows OS
-
C:\Program Files\RhinoSoft\Serv-U
Linux OS:
-
/usr/local/Serv-U
Install the hotfix
-
Shut down all running Serv-U processes.
-
Right-click the tray icon and select Stop Serv-U.
-
Right-click the tray icon and select Exit Tray.
-
Back up the following files and folders:
-
In Windows OS:
- <Serv-U-InstallDir>\Serv-U.exe
- <Serv-U-InstallDir>\Serv-U-Tray.exe
- <Serv-U-InstallDir>\Serv-U.dll
- <Serv-U-InstallDir>\Serv-U-RES.dll
- <Serv-U-InstallDir>\RhinoNET.dll
- <Serv-U-InstallDir>\RhinoRES.dll
- <Serv-U-InstallDir>\Client\Common\Scripts\functions.js
- <Serv-U-InstallDir>\Client\WebClientNew\
-
In Linux OS:
- <Serv-U-InstallDir>/Serv-U
- <Serv-U-InstallDir>/Client/Common/Scripts/functions.js
- <Serv-U-InstallDir>/Client/WebClientNew/
-
Extract the hotfix archive to a temporary location.
-
Open the folder for the platform on which Serv-U is installed.
For example, open the Linux/64-bit folder if Serv-U is installed on a 64-bit version of Linux.
-
On Linux, modify the permissions of the file by executing the following command:
chmod u+xs Serv-U
-
Copy the contents of this folder to your Serv-U installation directory.
-
Start the Serv-U Tray application.
-
Right-click the Serv-U Tray icon and select Start Serv-U.
The hotfix is installed.
Result
The issues listed at the top of the page are resolved.
Uninstall the hotfix
-
Shut down all running Serv-U processes.
-
Right-click the tray icon and select Stop Serv-U.
-
Right-click the tray icon and select Exit Tray.
-
Replace the following files and folders with the ones you backed up during installation:
-
In Windows OS:
- <Serv-U-InstallDir>\Serv-U.exe
- <Serv-U-InstallDir>\Serv-U-Tray.exe
- <Serv-U-InstallDir>\Serv-U.dll
- <Serv-U-InstallDir>\Serv-U-RES.dll
- <Serv-U-InstallDir>\RhinoNET.dll
- <Serv-U-InstallDir>\RhinoRES.dll
- <Serv-U-InstallDir>\Client\Common\Scripts\functions.js
- <Serv-U-InstallDir>\Client\WebClientNew\
-
In Linux OS:
- <Serv-U-InstallDir>/Serv-U
- <Serv-U-InstallDir>/Client/Common/Scripts/functions.js
- <Serv-U-InstallDir>/Client/WebClientNew/
-
Start the Serv-U Tray application.
-
Right-click the Serv-U application.
The hotfix is uninstalled.
For more information, contact Technical Support at https://serv-u.com/support.