Advertisement:

Author Topic: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released  (Read 2796028 times)

Offline emanuele

  • SMF Super Hero
  • *******
  • Posts: 14,161
  • Gender: Male
  • THERE'S JUST ME
SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« on: December 16, 2012, 05:05:30 PM »
Dear users,

Simple Machines Forum has released a security patch with version numbers: SMF 1.0.23, SMF 1.1.17 and SMF 2.0.3.
A security issue has been identified in all versions and is fixed with this patch, therefore it is recommended to make sure you update your forums immediately to ensure your community is safe.
In addition to the security patch, a few bug fixes to SMF 2.0.2 are also included within the patch for 2.0.x.
The most relevant bug fix is an issue that will arise in few months with PayPal: starting on February 1, 2013 PayPal will only accept headers which comply with the HTTP 1.1 specification.

If you are running 2.0.2, you can update your forum to 2.0.3 using the package manager. You should see the upgrade notification in the Admin panel and in the package manager, allowing you to download and install seamlessly. If you don't have a notification about the update, please run the scheduled task "Fetch Simple Machines files".
You can also download the patch for 2.0.2 from the customize site: smf_patch_2.0.3.tar.gz patch, and install it using the package manager.

If you are running 1.1.16, you can update to 1.1.17 with the smf_patch_1.0.23_1.1.17.tar.gz patch, also using the package manager.
If you are running SMF 1.0.22, take into consideration that this will most likely be the last patch for this version of SMF, which is reaching its "end of life". You can update to 1.0.23 with the smf_patch_1.0.23_1.1.17.tar.gz patch, also using the package manager.

If you use older versions of SMF, you can upgrade with the full upgrade packages from the downloads page.
Please find the changelog for the latest release, as usual, on the downloads page as well:
http://download.simplemachines.org/
If you are having problems downloading the patch from the admin panel, you can download the package from the upgrades page here:
http://custom.simplemachines.org/upgrades/
and install it like a mod.
Please refer also to the Online Manual for more details about:
* upgrading http://wiki.simplemachines.org/smf/Upgrading
* updating http://wiki.simplemachines.org/smf/Updating
* patching http://wiki.simplemachines.org/smf/Patching

Please do not use this topic for support requests. You will get a much quicker and better response by posting in the relevant support board!


Regards,
Simple Machines Forum

Update: 17/12/2012: there is still some issues with the upgrades page and the language packs that are not yet updated...sorry for the trouble.

Update: 18/12/2012: now everything should be fixed!
« Last Edit: December 20, 2012, 06:07:59 PM by emanuele »


Take a peek at what I'm doing! ;D



Hai bisogno di supporto in Italiano?

Aiutateci ad aiutarvi: spiegate bene il vostro problema: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.

Offline TrayBake

  • SMF Friend
  • SMF Super Hero
  • *
  • Posts: 21,367
  • Gender: Male
  • His Royal Runicness
    • bryan.deakin.1 on Facebook
    • pouvik on GitHub
    • @bryandeakin on Twitter
    • Dyspraxic Chat
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #1 on: December 16, 2012, 05:06:36 PM »
Great to see well done guys and gal :)
Bryan Runic Deakin
His Royal Runicness
Owner @ Bryan Deakin dot Com
Owner @ Dyspraxic Chat

Former Project Manager @ SMF
Former Vice President @ Simple Machines
Former Admin @ idesign360.com

Read my new poem "Memorial to the Pagan Boy"!!

Offline CoreISP

  • Server Admin
  • Server Team
  • SMF Super Hero
  • *
  • Posts: 13,445
  • Gender: Male
  • CoreISP.net
    • coreisp on Facebook
    • liroyvh on LinkedIn
    • @liroyvh on Twitter
    • CoreISP Corporation :: WebHosting, Dedicated Servers, and more!
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #2 on: December 16, 2012, 05:07:09 PM »
Congrats and well done! :)
- CoreISP.net Corporation -
  WebHosting, Colocation, Domain Registration & Network Services
- DedicatedBox.us Servers -
  Low priced Servers in a high-quality Network, the place for all your (advanced) server needs.
  We specialize in hosting big boards. Contact us!

((U + C + I)x(10 − S)) / 20xAx1 / (1 − sin(F / 10))
President/CEO of Simple Machines - Server Manager
Please do not PM for support - anything else is usually OK.

Offline Looking

  • SMF Hero
  • ******
  • Posts: 1,892
  • SMF Customization
    • SMF Custom Themes
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #3 on: December 16, 2012, 05:18:20 PM »
Thanks for the fixes.

Offline Antes

  • Evil Black Cat
  • Marketing
  • SMF Hero
  • *
  • Posts: 5,513
  • Gender: Male
  • Black cat rulz!
    • Antes on GitHub
    • merta on LinkedIn
    • @antesistan on Twitter
    • MMOBrowser
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #4 on: December 16, 2012, 05:22:30 PM »
Awesome :) well done
[ MMOBrowser ] # [ Raptr ] # [ Paid Translation Service ]

Quote from: Arantor
That's because cats are powered by sunlight and warmth

Offline DeVIL-I386

  • Semi-Newbie
  • *
  • Posts: 84
    • LinuxMintUsers.de
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #5 on: December 16, 2012, 05:24:15 PM »
If you don't have a notification about the update, please run the scheduled task "Fetch Simple Machines files".
Where should this option be hidden? Is it Administration Center » Maintenance » Forum Maintenance » Routine » Check all files against current versions?

This approach does not work. Tested in several forums.

That was at 2.0.1 and 2.0.2 also so that the update is displayed after about a week in the Admin Center.

Offline CoreISP

  • Server Admin
  • Server Team
  • SMF Super Hero
  • *
  • Posts: 13,445
  • Gender: Male
  • CoreISP.net
    • coreisp on Facebook
    • liroyvh on LinkedIn
    • @liroyvh on Twitter
    • CoreISP Corporation :: WebHosting, Dedicated Servers, and more!
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #6 on: December 16, 2012, 05:26:16 PM »
That actually works fine here :)
- CoreISP.net Corporation -
  WebHosting, Colocation, Domain Registration & Network Services
- DedicatedBox.us Servers -
  Low priced Servers in a high-quality Network, the place for all your (advanced) server needs.
  We specialize in hosting big boards. Contact us!

((U + C + I)x(10 − S)) / 20xAx1 / (1 − sin(F / 10))
President/CEO of Simple Machines - Server Manager
Please do not PM for support - anything else is usually OK.

Offline Colin

  • Customizer
  • SMF Hero
  • *
  • Posts: 6,708
  • Gender: Male
  • SMF Customizer
    • colinschoen on GitHub
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #7 on: December 16, 2012, 05:26:53 PM »
Nice work!
"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Offline emanuele

  • SMF Super Hero
  • *******
  • Posts: 14,161
  • Gender: Male
  • THERE'S JUST ME
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #8 on: December 16, 2012, 05:27:05 PM »
Where should this option be hidden? Is it Administration Center » Maintenance » Forum Maintenance » Routine » Check all files against current versions?
Almost but not exactly: admin > maintenance > scheduled tasks > scheduled tasks
Then under the column "run now" select the box corresponding to "Fetch Simple Machines Files", and click the button "run now".


Take a peek at what I'm doing! ;D



Hai bisogno di supporto in Italiano?

Aiutateci ad aiutarvi: spiegate bene il vostro problema: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.

Offline DeVIL-I386

  • Semi-Newbie
  • *
  • Posts: 84
    • LinuxMintUsers.de
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #9 on: December 16, 2012, 05:32:50 PM »
admin > maintenance > scheduled tasks > scheduled tasks
Then under the column "run now" select the box corresponding to "Fetch Simple Machines Files", and click the button "run now".
This works for me. Thank you!  :)

This way you should write to each announcement.

Offline Lord991

  • Semi-Newbie
  • *
  • Posts: 47
  • Gender: Male
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #10 on: December 16, 2012, 07:15:03 PM »
I need a step by step manual install because of my mods.

Its not added here 1.1.16 to 1.1.17  :-X

http://custom.simplemachines.org/upgrades/


Offline Road Rash Jr.

  • Sr. Member
  • ****
  • Posts: 765
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #11 on: December 16, 2012, 07:42:19 PM »
Great work. Can these older files be deleted?
SMF 2.0.1 Update
SMF 2.0.2 Update
Never argue with an Idiot like myself, they just drag you down to their level then beat you with experience.

Offline TrayBake

  • SMF Friend
  • SMF Super Hero
  • *
  • Posts: 21,367
  • Gender: Male
  • His Royal Runicness
    • bryan.deakin.1 on Facebook
    • pouvik on GitHub
    • @bryandeakin on Twitter
    • Dyspraxic Chat
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #12 on: December 16, 2012, 07:54:38 PM »
from your package manager ... its your choice ... btw nice to see you again :)
Bryan Runic Deakin
His Royal Runicness
Owner @ Bryan Deakin dot Com
Owner @ Dyspraxic Chat

Former Project Manager @ SMF
Former Vice President @ Simple Machines
Former Admin @ idesign360.com

Read my new poem "Memorial to the Pagan Boy"!!

Offline Road Rash Jr.

  • Sr. Member
  • ****
  • Posts: 765
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #13 on: December 16, 2012, 08:00:15 PM »
from your package manager ... its your choice ... btw nice to see you again :)
Thanks Bryan.
Never argue with an Idiot like myself, they just drag you down to their level then beat you with experience.

Offline Colin

  • Customizer
  • SMF Hero
  • *
  • Posts: 6,708
  • Gender: Male
  • SMF Customizer
    • colinschoen on GitHub
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #14 on: December 16, 2012, 08:05:34 PM »
I need a step by step manual install because of my mods.

Its not added here 1.1.16 to 1.1.17  :-X

http://custom.simplemachines.org/upgrades/
No need to download anything. Simply go to your package manager and install the upgrade when prompted.
"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Offline emanuele

  • SMF Super Hero
  • *******
  • Posts: 14,161
  • Gender: Male
  • THERE'S JUST ME
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #15 on: December 16, 2012, 08:18:08 PM »
@Lord it should be a caching issue. Sooner the new patches should appear.

ETA: anyway, you can view the manual edits at this address: http://custom.simplemachines.org/upgrades/index.php?action=upgrade;file=smf_patch_1.0.23_1.1.17.tar.gz;smf_version=1.1.16


Take a peek at what I'm doing! ;D



Hai bisogno di supporto in Italiano?

Aiutateci ad aiutarvi: spiegate bene il vostro problema: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.

Offline Eclipse16V

  • Sophist Member
  • *****
  • Posts: 1,068
  • Gender: Male
  • Tornado Map
    • Eclipse16V on Facebook
    • @Eclipse16V on Twitter
    • Tornado Map
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #16 on: December 17, 2012, 01:22:05 AM »
Thanks
I work with:
SMF 2 in German
Tornado Map

Offline 4Kstore

  • SMF Hero
  • ******
  • Posts: 4,165
  • Gender: Male
    • agustintari on Facebook
    • @agustintarifa on Twitter
    • SSIMPLE TEAM PAGE
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #17 on: December 17, 2012, 02:15:16 AM »
Thanks, I just translate this information to spanish.
http://www.simplemachines.org/community/index.php?topic=492796.0

NUEVOS MODS!!!

Offline codebirth

  • Jr. Member
  • **
  • Posts: 125
  • Gender: Male
  • Dark Knight
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #18 on: December 17, 2012, 02:16:27 AM »
Where should this option be hidden? Is it Administration Center » Maintenance » Forum Maintenance » Routine » Check all files against current versions?
Almost but not exactly: admin > maintenance > scheduled tasks > scheduled tasks
Then under the column "run now" select the box corresponding to "Fetch Simple Machines Files", and click the button "run now".

Thank you. Smooth upgrade.

Offline Colin

  • Customizer
  • SMF Hero
  • *
  • Posts: 6,708
  • Gender: Male
  • SMF Customizer
    • colinschoen on GitHub
Re: SMF 2.0.3, 1.1.17 and 1.0.23 security patches released
« Reply #19 on: December 17, 2012, 02:46:56 AM »
Thanks for the feedback. That is what we like to hear.
"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.