<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.osnexus.com/index.php?action=history&amp;feed=atom&amp;title=Security_Update_Archive</id>
	<title>Security Update Archive - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.osnexus.com/index.php?action=history&amp;feed=atom&amp;title=Security_Update_Archive"/>
	<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Security_Update_Archive&amp;action=history"/>
	<updated>2026-10-09T16:38:16Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.42.1</generator>
	<entry>
		<id>https://wiki.osnexus.com/index.php?title=Security_Update_Archive&amp;diff=11539&amp;oldid=prev</id>
		<title>Qadmin: Created page with &quot; == Linux Base OS Security Fixes / Notifications ==  Security notifications for QuantaStor base OS packages are now available at the OSNEXUS Security Notices site (http://serv...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.osnexus.com/index.php?title=Security_Update_Archive&amp;diff=11539&amp;oldid=prev"/>
		<updated>2019-03-21T18:02:39Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot; == Linux Base OS Security Fixes / Notifications ==  Security notifications for QuantaStor base OS packages are now available at the OSNEXUS Security Notices site (http://serv...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&lt;br /&gt;
== Linux Base OS Security Fixes / Notifications ==&lt;br /&gt;
&lt;br /&gt;
Security notifications for QuantaStor base OS packages are now available at the OSNEXUS Security Notices site (http://services.osnexus.com/security)&lt;br /&gt;
&lt;br /&gt;
== Core Product Security Updates ==&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 4.5.0 (March 9th 2018) ===&lt;br /&gt;
* Kernel 4.4.0-112 includes fixes for the below Security items:&lt;br /&gt;
** Spectre - Variant 1 - CVE-2017-5753 &lt;br /&gt;
** Meltdown - Variant 3 - CVE-2017-5754 &lt;br /&gt;
&lt;br /&gt;
* Note: Spectre Variant 2 CVE-2017-5715 is a firmware code issue and can only be addressed with updated microcode in a Motherboard BIOS or firmware update from the Processor manufacturer.&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 4.3.1 (June 30th 2017) ===&lt;br /&gt;
* Fixed a Security issue with bad password responses. Fixes items found related to CVE-2017-9978&lt;br /&gt;
* Fixed the Rest API response for when a method is unsupported. Fixes items found related to CVE-2017-9979&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 4.1.5 (Jan 18th 2017) ===&lt;br /&gt;
* Fixed: Addressed SSL concern CVE-2016-2183 (SWEET32) with updated qsciphers file to remove DES and 3DES ciphers.&lt;br /&gt;
* Fixed: disabled tomcat web port 8443.&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 4.0.8 (Nov 18th 2016) ===&lt;br /&gt;
* Adds new 3.19.0-73 Linux kernel that includes updates and a security patch to address CVE-2016-5195 (Dirty COW)&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 4.0.0 (March 31st 2016) ===&lt;br /&gt;
* Fixed: Addressed CVE-2015-4000 (Logjam) in the Web Server Package with increase of the default Modulus length to 2048-bit and removal of weak DHE Diffie-Hellman ciphers.&lt;br /&gt;
* Added: New QuantaStor users created via the Users and Groups section of the Web Manager or &amp;#039;qs user-add&amp;#039; CLI command will now have the same User ID on all QuantaStor nodes. The new UID range is 100000000-199999999.&lt;br /&gt;
* Fixed: An unexpected web request to the Web Server will now correctly route to a 404 error page.&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 3.15.1 (May 28th 2015) ===&lt;br /&gt;
* adds [http://wiki.osnexus.com/index.php?title=Firewall_Configuration firewall support] for disabling access to unused storage services&lt;br /&gt;
* fix to support creation of roles with no permissions&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 3.15.0 (May 1st 2015) ===&lt;br /&gt;
* adds support for customizing the pem files for all services (core qs_service, REST service, and Tomcat)&lt;br /&gt;
* adds support for customizing the SSL ciphers, applies strong cipher limits automatically&lt;br /&gt;
* adds SSL cert generation script which deposits custom certs into /var/opt/osnexus/quantastor/ssl which are automatically picked up by REST and core services&lt;br /&gt;
* adds script command to upgrade from Java 6 to Java 7 (qs-util java7upgrade), which allows browsers to connect via https using stronger ciphers / TLS 1.2&lt;br /&gt;
* fix to disable all use of SSLv3 across all internal services (Core service, Tomcat, REST API service) in favor of TLS for improved security / HIPAA compliance&lt;br /&gt;
* fix to allow removal of duplicate &amp;#039;admin&amp;#039; users&lt;br /&gt;
* fix to remove duplicate user entries in Samba config when user assigned as &amp;#039;Admin&amp;#039; on a share&lt;br /&gt;
* fix to password length enforcement (8-34 char)&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 3.12.2 (July 22nd 2014) ===&lt;br /&gt;
* fix to set password error message to show 8 to 40 characters required&lt;br /&gt;
* fix to update user password changes to all grid nodes&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 3.12.0 (June 27th 2014) ===&lt;br /&gt;
* adds new https keystore for web management interface (be sure to clear your browser cache)&lt;br /&gt;
* adds secure mode &amp;#039;qs-util disablehttp&amp;#039; to enable/disable http access (port 80) to force admins to use https for web management&lt;br /&gt;
* fix to core service to allow for changing openssl pem files&lt;br /&gt;
&lt;br /&gt;
=== QuantaStor 3.9.3 (March 7th 2014) ===&lt;br /&gt;
* fix to AD domain leave operation to remove AD computer entry&lt;/div&gt;</summary>
		<author><name>Qadmin</name></author>
	</entry>
</feed>