A new security advisory for ColdFusion is now available
A Security Advisory (APSA13-01) has been posted in regards to security issues in ColdFusion for Windows, Macintosh and UNIX. There are reports that these vulnerabilities are being exploited in the wild against ColdFusion customers. Information regarding these vulnerabilities, including mitigation recommendations, is provided in the Security Advisory. We are in the process of finalizing a fix for the issues and expect a hotfix will be available on January 15, 2013.
Using the description from PSIRT blog and cross posting here.
10 comments so far ↓
Thanks!,
-Aaron
CVE-2013-0625, CVE-2013-0629, CVE-2013-0631, CVE-2013-0632
Thanks!,
-Aaron
ColdFusion 10 Update 7 - Continue installation
ColdFusion 10 Update 6 - Continue installation
Progress Information
Progress Information
Error
Confirm overwrite
Uninstall Confirmation
Server version is 10,0,5,283319
I tried to install just update 6 and nothing happens when I push the download & install button.
Can please let me know the corresponding log from the following file:
<ColdFusion10Home>\cfusion\logs\update.log ?
Has <ColdFusion10Home>\cfusion\hf-updates\hf-10-00006 been created and is there any log file there.
If it is there you can mail me AT krishnapATadobeDOTcom
I have tried copying the updates.xml file from backup and restarting but it tells me no updates have been applied and i am unable to download any.
I'm going to uninstall update 7 manually and see if that fixes things. If you have seen this before and know how to fix it please post the answer as this is the top thread on google when searching the error :-)
Please download the hotfix directly from:
http://download.adobe.com/pub/adobe/coldfusion/hotfix_008.jar
and then open the command prompt (with Run as Administrator" option for all Vista/Win7/Win8 family OSes)
Then run the just downloaded jar file from command prompt:
First cd to where it is downloaded. and then run as follows. Change path as per your installation.
>C:\ColdFusion10\jre\bin\java -jar hotfix_008.jar
Thanks,
Krishna
I DO wish though that Adobe made it a lot easier to find the .jar files to download. It seems that I have to waste a ton of time hunting around between various pages talking about the hotfix but not actually giving a download link for it.
CVE-2013-0625, CVE-2013-0629, CVE-2013-0631, CVE-2013-0632
Thanks!
Leave a Comment