Webmin version 1.760 released

7 posts / 0 new
Last post
#1 Fri, 07/03/2015 - 19:57
Joe
Joe's picture

Webmin version 1.760 released

Howdy all,

I've just finished rolling out Webmin version 1.760 for all Virtualmin repositories.

Changes since 1.750:

  • Added the FirewallD module, for configuring the new default firewall seen on CentOS and RHEL 7.
  • More German, Norwegian and Catalan translation updates.
  • Fixed a bug that allowed the xmlrpc.cgi script to be used in an XSS attack (thanks to Peter Allow from IBM).

Note that this includes a security bug fix for an XSS vulnerability in the XML-RPC mechanism in Webmin (http://webmin.com/security.html) so updating as soon as possible is recommended.

Also, this includes a new module for firewalld, which is a large chunk of new code, so is in need of user testing across a wide variety of systems. So, if you use firewalld, please try out the module and report bugs or major usability issues. We don't use firewalld on our own servers (it's extremely limited for servers, compared to using iptables directly, especially for bridge or tun interfaces), so my experience with it is limited. But, it's been very frequently requested since CentOS 7/RHEL 7 made it the default for managing firewalls, so Jamie dug in and made a new module over the past couple of weeks (because Jamie is amazing).

As always, file bugs in the tracker, ask questions in the forums (or if you're a Virtualmin Pro or Cloudmin Pro user and you need a fast response, you can ask questions in the tracker).

Mon, 07/06/2015 - 07:01
jimdunn

Joe, I see the 1.760 update available when logging into Virtualmin

"Webmin version 1.760 is now available, but you are running version 1.750"

but I still do not see it at the command line, when doing "apt-get update ; apt-get upgrade"

Just an FYI. Thx!

Mon, 07/06/2015 - 10:32
andreychek

Which distro/version are you using?

-Eric

Tue, 07/07/2015 - 08:07
jimdunn

UPDATE: As of 9am, Tue. July 7, the webmin 1.760 was just offered via apt-get on my licensed server.

The webmin 1.760 is still not being offered on my 3 GPL servers.

Tue, 07/07/2015 - 10:23 (Reply to #4)
andreychek

Thanks, we're looking into this!

Thu, 07/09/2015 - 11:13
q7joey

i've been posting about this issue on the virtualmin forum for a while now and not getting any traction.

the webmin and usermin recent updates are not showing up for rhel or ubuntu based systems when using the virtualmin repos.

Fri, 07/10/2015 - 08:55
q7joey

i am now seeing webmin 1.760 showing up for centos and ubuntu systems. is usermin 1.670 soon to follow?