ホーム > フォーラム > Release of XOOPS 2.0.13 JP

Release of XOOPS 2.0.13 JP
投稿者: ayumi | 投稿日時: 2005-10-24 20:31 | 閲覧: 6758回
ayumi
XOOPS Cube Development Team is pleased to announce the release of XOOPS 2.0.13 JP. It includes some fixes for security bugs that allowed hijacking of session variables by XSS. It is strongly recommended that all users using any of the previous versions of XOOPS including 2.0.12 upgrade to this latest version.

Download full package / Download upgrade package from XOOPS 2.0.12 JP

Download full package
Download upgrade package from XOOPS 2.0.12 JP
Download upgrade package from XOOPS 2.0.13 JP

===========================
2005/ 10/ 15: Version 2.0.13 JP
Security fixes in
- class/module.textsanitizer.php
- class/module.textsanitizer.php
- include/functions.php
- class/comment_renderer.php
- modules/system/admin/comments/main.php
- modules/newbb/index.php
- modules/newbb/viewforum.php
- modules/newbb/viewtopic.php
- misc.php

- Fix Contact module (For vulnerability may cause bulk email distribution)
- Add function to check file format in the MediaUploader
- Change initial value of the PHP debug mode (Default value ON)

Two vulnerabilities in this release reported by Keigo Yamazaki, LAC:Little eArth Corporation Co., Ltd. with JPCERT/CC security team. We thank them for their work.

コメント(4)

新しいものから | 古いものから | ネスト表示 | RSS feed
Re: Release of XOOPS 2.0.13 JP 
Re: Release of XOOPS 2.0.13 JP (portuguese translation) 
投稿者: Mikhail | 投稿日時: 2005-10-25 0:04
Mikhail
Portuguese translation (non literal).

A equipe de desenvolvimento do XOOPS CUBE acaba de lançar a versão 2.0.13 do produto, que inclui alguns reparos para possíveis brechas que permitiram ataques de sessão do tipo “hijacking”, lançando variáveis via XSS. Recomenda-se enfaticamente que todos os utilizadores das versões precedentes, incluindo a 2.0.12, atualize os seus websites para esta versão.

Descargas (downloads):
- XOOPS Version 2.0.13 JP
- XOOPS 2.0.13 JP em português
- Apenas os arquivos de atualização
da versão 2.0.12 para a 2.0.13.

2005/ 10/ 15: Version 2.0.13 JP
O aumento da segurança foi realizado com alterações nos seguintes arquivos:
- class/module.textsanitizer.php
- class/module.textsanitizer.php
- include/functions.php
- class/comment_renderer.php
- modules/system/admin/comments/main.php
- modules/newbb/index.php
- modules/newbb/viewforum.php
- modules/newbb/viewtopic.php
- misc.php

Outros ajustes:

- Corrigida uma falha que poderia permitir o envio de ‘spam’ pelo módulo de contato (/contact).

- Desenvolvida uma função especialmente para verificar a validade dos formatos dos arquivos enviados pelo MediaUploader.

- Alterado o valor inicial do depurador PHP, que vinha habilitado na instalação.

E mais duas vulnerabilidades até então desconhecidas foram alertadas graças ao Keigo Yamazaki, da LAC (Little eArth Corporation Co., Ltd.) juntamente com a equipe de segurança do JPCERT/CC, a quem a equipe do XOOPS Cube gostaria de agradecer.
Release of XOOPS 2.0.13a JP 
投稿者: ayumi | 投稿日時: 2005-10-25 23:20
ayumi
We would like to announce the release of XOOPS 2.0.13a JP, re-packaged release version of the XOOPS 2.0.13JP.

The release of XOOPS 2.0.13JP lacks the file of - modules/system/admin/comments/main.php. Also, the version includes $HTTP_*_VAR which should be replaced to $_* for PHP5 compatibilities.

We apologize for any inconvenience of the release.

Download full package
Download upgrade package from XOOPS 2.0.12 JP
Download upgrade package from XOOPS 2.0.13 JP

XOOPS Cube Development Team
Release of XOOPS 2.0.13a JP / Security advisories 
投稿者: ayumi | 投稿日時: 2005-10-26 17:07
ayumi
Concerning vulnerabilities that were fixed in 2.0.13JP/2.0.13aJP, there are announcements from security advisories.

Xoops Multiple Script Insertion Vulnerabilities
http://secunia.com/advisories/17300/
XOOPS Multiple Cross-site Scripting Vulnerabilities
http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/85_e.html

Just FYI.

    投票(0)

    新しいものから | 古いものから | RSS feed
     

    概要 | ダウンロード | ニュース | フォーラム | 開発情報 | ツール | テーマ | モジュール
    お問い合わせ | プライバシーポリシー
    Copyright © 2001-2012 XOOPS Cube日本サイト