Kruge
Mar 14 2002, 11:11 AM
I`m wondering if anyone has tried to update zlib on their plesk machine since the vuln was announced.
I really want to get this cleared up, but I`m afraid of breaking anything which plesk relies upon.
Anyone brave enough to have attempted it yet ?
winston
Mar 14 2002, 04:24 PM
It works fine for me (but I don't use plesk). I don't see any reason why it'd hurt plesk. Just get the updated RPM and install.
webbcite
Mar 14 2002, 04:34 PM
but don't you then have to recompile all your programs that use zlib to use the new version?
bobk
Mar 15 2002, 04:29 PM
I've seen some references saying that "lots of software" links zlib statically (which would mean that you'd have to update the package). I assume that if any RPM package needed updating, it would be announced as a separate security update for that package. But I'm not sure how many packages really do static linking to zlib; I've heard of none that are in the critical security perimeter, suspect it might be mostly image manipulation and such.
OpenSSH had no problems with the zlib update from RedHat. I use up2date, and the recent OpenSSH and the zlib patches both worked fine for me.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.