Nexology Community
 
     
 
   

Go Back   Nexology Community > Support Zone > Security and Release information

Reply
 
LinkBack Thread Tools Display Modes
Old 10-13-2003, 05:39 PM   #1
Moderator
 
MikeMann's Avatar
 
Join Date: Jun 2002
Location: Los Angeles CA
Posts: 7,532
Geeklog 1.3.8-1sr1

This version is a security update release over 1.3.8-1. This is being released in response to the recent reports about (confirmed and unconfirmed) security issues in Geeklog.

From the history file inside the .tar.gz file:

"GeekLog History/Changes:

October 12, 2003 (1.3.8-1sr1)
----------------

This release is intended to address some of the security issues reported in September and early October 2003.

1. Includes Ulf Harnhammar's kses HTML filter to address possible Javascript injections and CSS defacements.

When upgrading from an earlier version, please make sure to copy over the $_CONF['user_html'] and $_CONF['admin_html'] arrays from the included config.php to your own copy of that file.

2. While almost all of the alleged SQL injection issues could not be
reproduced, this release includes an update to the MySQL class to not report SQL errors in the browser any more (but only in Geeklog's error.log). This will avoid disclosing any sensitive information as part of the error message.

Please note that at the moment we do NOT recommend to use Geeklog with MySQL 4.1 (which, at the time of this writing, is in alpha state and should not be used on production sites anyway).

An upcoming release of Geeklog will address the remaining SQL issues, including any problems with MySQL 4.1.

Other fixes (not security-related):

- When trying to guess the value of $_CONF['cookiedomain'], we need to remove the port number from the URL, if there is one (bug #75).
- The full 1.3.8-1sr1 tarball also includes updated French (Canada) and Turkish language files.
__________________
Michael Mann

Michael Mann Desktop Publishing
Me On the Net: Facebook | Twitter

Read My Writing

Need a notary in Los Angeles?
I'm a mobile notary
MikeMann is offline   Reply With Quote
Old 10-14-2003, 07:53 AM   #2
HaveANiceDay
 
middleground's Avatar
 
Join Date: Apr 2002
Location: MacTopia
Posts: 4,167
Thanks Mike
__________________
Every Day Above Ground Is A Good One !!

"A word to the wise ain't necessary -- it's the stupid ones that need the advice." -- Bill Cosby

MiddleGround | MGWebDomains.com | MGWebDomains.net

"With the Heart and Mind united in a single Perfect Sphere." (Neil Peart)
middleground is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 10:25 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 RC1
Copyright ©2001 - 2009, HostNexus