URGENT — Security Advisory
LiteSpeed has released a further security update for LiteSpeed Web Server Enterprise: v6.3.7 build 2.
This release further hardens the lscgid CGI helper as part of the ongoing response to the recently disclosed privilege-escalation vulnerability.
Affected: LiteSpeed Web Server Enterprise installations not running v6.3.7 build 2 or later
Status: Additional security fix available
Action required: Update immediately
ACTION REQUIRED (immediately)
Even if you have already updated to v6.3.7, please upgrade again to:
LiteSpeed Web Server Enterprise v6.3.7 build 2 or later
Check Your Installed Version and Build
Run the following commands as root:
/usr/local/lsws/bin/lshttpd -v
cat /usr/local/lsws/BUILD
Update LiteSpeed Web Server Enterprise
Run the following command as root to update to the latest v6.3.7 release:
/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7
After the update completes, restart LiteSpeed:
/usr/local/lsws/bin/lswsctrl restart
This update includes:
[Security] Further harden lscgid.
We strongly recommend applying this latest release as soon as possible to ensure your server receives all available protections related to this issue.
After upgrading, please verify normal operation of CGI applications and server-level logging tools.
If you need assistance with the upgrade or have concerns about possible exposure, our support team is ready to help.
Thank you for your immediate attention to this security update.
LiteSpeed Team
To update
/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 -b 2
systemctl restart lshttpd