Question

Flexsera license service has an exploit. Update is availble but no safe version yet on download page

  • 7 December 2017
  • 4 replies
  • 0 views

See: https://nvd.nist.gov/vuln/detail/CVE-2016-10395

We need to update the Safe License server which you currently only provide up to version 11.13.


4 replies

Badge +6
Hi @hennyhoeven,

 

 

We are currently investigating this issue - we will be sure to update this thread with additional information once we have the fix in place. Our apologies for any inconvenience this may have caused, and thank you for bringing this to our attention.

 

 

-Annabelle

 

@gertatvicrea

It seems that Flexera version 11.15 became already available in November 2017

Userlevel 4
Badge +13
Safe PR: 80879

 

 

Userlevel 4
Badge +13

We have now upgraded the FlexNet installers available on the downloads page of our website to version 11.15 for FME Desktop floating licenses. We recommend upgrading all FME floating license servers to guard against this vulnerability and also because future license files will not be compatible with previous versions of the FME floating license server. A new license file is not required and your existing safe.lic file should continue work. Also, note that this upgrade applies to FME Desktop Floating license servers and does not apply to current FME Server licensing.

Steps for Windows FME Desktop Floating License Server upgrades:

  1. Using the LMTOOLS application - Config Services panel, confirm the location of the safe.lic license file
  2. Stop the FME License Server service also using the LMTOOLS application
  3. Download the appropriate new Floating License Installer from the Safe Software downloads page
  4. Uninstall the existing "FlexNet for Safe Software" using Control Panel > Programs and Features
  5. Install the new downloaded Floating License Installer
  6. Use the application LMTOOLS - Config Services panel to ensure there is an "FME License Server" service and that the Path to License File field shows a valid path to the safe.lic license file*
  7. Start the FlexServer using LMTOOLS and save the service if any changes were made
*Note that if do not install the same type of floating license server you had previously, for example, if you had the Windows 32 bit server and you upgrade to the Windows 64 bit version, then you may need to copy the safe.lic license file from the previous flexserver path into the new path defined in LMTOOLS. Steps Upgrading the FME Desktop Floating License Server for Linux or Mac Systems

Note that your system administrator may have configured automatic start-up of your floating license server after system restart and therefore you will need to either restart the system after these steps or restart the license server using the same command used in the start-up script.

  1. Download the appropriate package from the Safe Software downloads page.
  2. Locate your FlexServer directory. In the original documentation this directory was defined as /opt/FlexServer but it could be user-defined.
  3. Stop the floating license server with the command % ./lmutil lmdown -c <path_to_safe.lic>
  4. Backup and then replace the files in your <FlexServer> directory with the files in the downloaded package.
  5. Restart the floating license server using the same command used initially to start the license server. By default the command is % ./lmgrd -c ./safe.lic -l safe.log but your system administrator may have modified the path to the license file or to the floating license log to suit your own environment and may have placed this command in a start-up script.
Please consult the FME Administrator guide for detailed steps on installing new FME Floating License Servers.

Reply