oss-sec mailing list archives

Re: CVE request: cmsmadesimple < 1.8.1


From: Josh Bressers <bressers () redhat com>
Date: Mon, 2 Aug 2010 15:57:39 -0400 (EDT)

Please use CVE-2010-2797

Thanks.

-- 
    JB


----- "Hanno Böck" <hanno () hboeck de> wrote:

http://www.cmsmadesimple.org/2010/07/3/announcing-cms-made-simple-1-8-1-
mankara/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+cmsmadesimple%2Fblog+%28CMS+Made+Simple%29

 NOTE: This release fixes an important security vulnerability,
we recommend that ALL users upgrade as soon as possible.

The local inclusion vulnerability fixed is old and affects many
previous versions of CMSMS. Therefore it is important for ALL
installations to be upgraded as soon as possible.

This release also fixes all of the issues encountered with the
CMSMS 1.8 release due to the overhaul of the translation function.
Your performance in the admin section should be back to normal
following this upgrade.

Below is a complete list of the remaining issues that have been
addressed in this release, enjoy.

Version 1.8.1 - Mankara


Security:

    Fixed local inclusion security flaw
-- 
Hanno Böck            Blog:           http://www.hboeck.de/
GPG: 3DBD3B20         Jabber/Mail:    hanno () hboeck de

http://schokokeks.org - professional webhosting


Current thread: