cpg1.4.26 Security release - upgrade mandatory! cpg1.4.26 Security release - upgrade mandatory!
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

cpg1.4.26 Security release - upgrade mandatory!

Started by Αndré, January 28, 2010, 11:41:28 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Αndré

The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.4.25 or older update to this latest version as soon as possible.

How to update:
Users running versions prior to 1.4.26 should update immediately by downloading the latest version from the download page and following the upgrade steps in the documentation.

For those who want to apply the vulnerability fix manually to their Coppermine installation, open upload.php, find
echo "<tr><td>{$URI_failure_array[$i]['failure_ordinal']} {$URI_failure_array[$i]['URI_name']}</td><td>{$URI_failure_array[$i]['error_code']}</td></tr>";
and replace with
echo "<tr><td>{$URI_failure_array[$i]['failure_ordinal']} ".htmlentities($URI_failure_array[$i]['URI_name'])."</td><td>{$URI_failure_array[$i]['error_code']}</td></tr>";

Support:
If you have problems with this update, please use the Update support board. Do not post your issues to this announcement thread - your post will be deleted without notice.

Why was cpg1.4.26 released?
The release covers a recently discovered input validation vulnerability that allows (if unpatched) a malevolent visitor to include own script routines (thread).

Additionally, cpg1.4.26 includes fixes for the following non-security related issues:

  • Edited vBulletin bridge to reflect changes from vB3.x to vB4.x
  • Added check to plugin manager for version requirements - backported feature from cpg1.5.x (thread)
  • Updated Italian Language file
  • Fixed permission check in crop/rotate wrongly denying access
  • Fixed caching issues with xp publisher
  • Fixed issue with creating albums in xp publisher with MySQL's strict mode enabled
  • Fixed bridge issue when creating albums in xp publisher
  • Updated German language files (added missing strings)
  • Updated MyBB bridge to 1.4
  • Updated Czech language file (user contribution)
  • Updated Slovak language file (user contribution)
  • Updated Italian language file (user contribution)

Thanks to Aditya Mooley for coming up with the fix, and thanks to Ivan Buetler and the GESEC Team for discovering the vulnerability.


Thanks,
The Coppermine Team

François Keller

Avez vous lu la DOC ? la FAQ ? et cherché sur le forum avant de poster ?
Did you read the DOC ? the FAQ ? and search the board before posting ?
Mon Blog

Fabricio Ferrero

Read Docs and Search the Forum before posting. - Soporte en español
--*--
Fabricio Ferrero's Website

Catching up! :)

Makc666

#3
Russian Announcement here.
Объявление на Русском здесь. (ISO-8859-1)
Îáúÿâëåíèå íà Ðóññêîì çäåñü. (Windows-1251)