Topic: IMPORTANT: Two new vulnerabilities in 0.9.6.1  (Read 16016 times)

Pages: [1]   Go Down

#1: 2-Jan-2008, 11:22 AM

Foundation

OpenGeek
MODx Co-Founder
Posts: 6,713

damn accurate caricatures...

WWW
Please take notice that two security vulnerabilities have been reported and confirmed in 3rd-party scripts that are included in the MODx 0.9.6.1 distributions.  Please see http://www.securityfocus.com/archive/1/485707/30/0/threaded for details.

You need to take immediate action to protect your site( s ). 

For 0.9.6.1
Go to http://svn.modxcms.com/trac/tattoo/changeset/3281 and you can choose from three options for applying the changes to your existing installations: download the zip archive from the link at the bottom (http://svn.modxcms.com/trac/tattoo/changeset/3281?format=zip&new=3281) and overwrite your existing files, get the unified diff (http://svn.modxcms.com/trac/tattoo/changeset/3281?format=diff&new=3281) and apply as a patch, or apply the diffs detailed on the page manually.

For 0.9.6
Same as above, though I recommend upgrading to 0.9.6.1 first to make sure you have the latest bug fixes.

Alternative for 0.9.6 or before...
Grab the latest trunk from SVN and upgrade your installation normally.


Additional information, and an 0.9.6.2 official release with these patches included will be available shortly.
« Last Edit: 2-Jan-2008, 01:50 PM by OpenGeek »
Jason Coward
MODx Co-Founder
xPDO Founder
CTO @ Collabpad
work productively.
work intelligently.
work together.
Light is just a vibration of a note too. Everything is. You've got to keep that in mind.
  Frank Zappa

#2: 2-Jan-2008, 01:52 PM

Foundation

OpenGeek
MODx Co-Founder
Posts: 6,713

damn accurate caricatures...

WWW
FYI, trunk has been patched with solutions to both of these security fixes and I will be in the process of notifying all of the reporting services so they publish this information; see the original post for updated information.
Jason Coward
MODx Co-Founder
xPDO Founder
CTO @ Collabpad
work productively.
work intelligently.
work together.
Light is just a vibration of a note too. Everything is. You've got to keep that in mind.
  Frank Zappa

#3: 22-Jan-2008, 01:21 PM

Foundation

rthrash
Posts: 11,282

WWW
admin note: clarified for those with feed readers who don't see the entire thread in context

The current download available at the MODx download site was replaced by a version containing the patches for 0961 in this thread. 0962 will also contain these patches as Jason mentioned. If you've not applied the security patch already (shame on you!), you can either grab it via the instructions listed above or just download the complete installer from the downloads page and install via the normal upgrade mode. If you're not running this latest patched version, now would be a very good time to upgrade.
« Last Edit: 23-Jan-2008, 12:39 PM by rthrash »
MODx is a content managmeent framework that allows web professionals to turn over sites to end-users for daily maintenance without worrying. Please help us help you when asking for assistance and read the wiki. Searching the forums from the top level helps, too.
Ryan Thrash
MODx Co-Founder
Principal @ Collabpad
work productively.
work intelligently.
work together.
Pages: [1]   Go Up
0 Members and 1 Guest are viewing this topic.