News:

Bored?  Looking to kill some time?  Want to chat with other SMF users?  Join us in IRC chat or Discord

Main Menu

SMF 2.0.3, 1.1.17 and 1.0.23 security patches released

Started by emanuele, December 16, 2012, 05:05:30 PM

Previous topic - Next topic

emanuele

Dear users,

Simple Machines Forum has released a security patch with version numbers: SMF 1.0.23, SMF 1.1.17 and SMF 2.0.3.
A security issue has been identified in all versions and is fixed with this patch, therefore it is recommended to make sure you update your forums immediately to ensure your community is safe.
In addition to the security patch, a few bug fixes to SMF 2.0.2 are also included within the patch for 2.0.x.
The most relevant bug fix is an issue that will arise in few months with PayPal: starting on February 1, 2013 PayPal will only accept headers which comply with the HTTP 1.1 specification.

If you are running 2.0.2, you can update your forum to 2.0.3 using the package manager. You should see the upgrade notification in the Admin panel and in the package manager, allowing you to download and install seamlessly. If you don't have a notification about the update, please run the scheduled task "Fetch Simple Machines files".
You can also download the patch for 2.0.2 from the customize site: smf_patch_2.0.3.tar.gz patch, and install it using the package manager.

If you are running 1.1.16, you can update to 1.1.17 with the smf_patch_1.0.23_1.1.17.tar.gz patch, also using the package manager.
If you are running SMF 1.0.22, take into consideration that this will most likely be the last patch for this version of SMF, which is reaching its "end of life". You can update to 1.0.23 with the smf_patch_1.0.23_1.1.17.tar.gz patch, also using the package manager.

If you use older versions of SMF, you can upgrade with the full upgrade packages from the downloads page.
Please find the changelog for the latest release, as usual, on the downloads page as well:
http://download.simplemachines.org/
If you are having problems downloading the patch from the admin panel, you can download the package from the upgrades page here:
http://custom.simplemachines.org/upgrades/
and install it like a mod.
Please refer also to the Online Manual for more details about:
* upgrading http://wiki.simplemachines.org/smf/Upgrading
* updating http://wiki.simplemachines.org/smf/Updating
* patching http://wiki.simplemachines.org/smf/Patching

Please do not use this topic for support requests. You will get a much quicker and better response by posting in the relevant support board!


Regards,
Simple Machines Forum

Update: 17/12/2012: there is still some issues with the upgrades page and the language packs that are not yet updated...sorry for the trouble.

Update: 18/12/2012: now everything should be fixed!


Take a peek at what I'm doing! ;D




Hai bisogno di supporto in Italiano?

Aiutateci ad aiutarvi: spiegate bene il vostro problema: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.

Deaks

~~~~
Former SMF Project Manager
Former SMF Customizer

"For as lang as hunner o us is in life, in nae wey
will we thole the Soothron tae owergang us. In truth it isna for glory, or wealth, or
honours that we fecht, but for freedom alane, that nae honest cheil gies up but wi life
itsel."

LiroyvH

((U + C + I)x(10 − S)) / 20xAx1 / (1 − sin(F / 10))
President/CEO of Simple Machines - Server Manager
Please do not PM for support - anything else is usually OK.


Antes


DeVIL-I386

Quote from: emanuele on December 16, 2012, 05:05:30 PM
If you don't have a notification about the update, please run the scheduled task "Fetch Simple Machines files".
Where should this option be hidden? Is it Administration Center » Maintenance » Forum Maintenance » Routine » Check all files against current versions?

This approach does not work. Tested in several forums.

That was at 2.0.1 and 2.0.2 also so that the update is displayed after about a week in the Admin Center.

LiroyvH

((U + C + I)x(10 − S)) / 20xAx1 / (1 − sin(F / 10))
President/CEO of Simple Machines - Server Manager
Please do not PM for support - anything else is usually OK.

Colin

"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin

emanuele

Quote from: DeVIL-I386 on December 16, 2012, 05:24:15 PM
Where should this option be hidden? Is it Administration Center » Maintenance » Forum Maintenance » Routine » Check all files against current versions?
Almost but not exactly: admin > maintenance > scheduled tasks > scheduled tasks
Then under the column "run now" select the box corresponding to "Fetch Simple Machines Files", and click the button "run now".


Take a peek at what I'm doing! ;D




Hai bisogno di supporto in Italiano?

Aiutateci ad aiutarvi: spiegate bene il vostro problema: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.

DeVIL-I386

Quote from: emanuele on December 16, 2012, 05:27:05 PM
admin > maintenance > scheduled tasks > scheduled tasks
Then under the column "run now" select the box corresponding to "Fetch Simple Machines Files", and click the button "run now".
This works for me. Thank you!  :)

This way you should write to each announcement.

Lord991

I need a step by step manual install because of my mods.

Its not added here 1.1.16 to 1.1.17  :-X

http://custom.simplemachines.org/upgrades/


Road Rash Jr.

Great work. Can these older files be deleted?
SMF 2.0.1 Update
SMF 2.0.2 Update
Never argue with an Idiot like myself, they just drag you down to their level then beat you with experience.

Deaks

from your package manager ... its your choice ... btw nice to see you again :)
~~~~
Former SMF Project Manager
Former SMF Customizer

"For as lang as hunner o us is in life, in nae wey
will we thole the Soothron tae owergang us. In truth it isna for glory, or wealth, or
honours that we fecht, but for freedom alane, that nae honest cheil gies up but wi life
itsel."

Road Rash Jr.

Quote from: Scrooge on December 16, 2012, 07:54:38 PM
from your package manager ... its your choice ... btw nice to see you again :)
Thanks Bryan.
Never argue with an Idiot like myself, they just drag you down to their level then beat you with experience.

Colin

Quote from: Lord991 on December 16, 2012, 07:15:03 PM
I need a step by step manual install because of my mods.

Its not added here 1.1.16 to 1.1.17  :-X

http://custom.simplemachines.org/upgrades/
No need to download anything. Simply go to your package manager and install the upgrade when prompted.
"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin

emanuele

@Lord it should be a caching issue. Sooner the new patches should appear.

ETA: anyway, you can view the manual edits at this address: http://custom.simplemachines.org/upgrades/index.php?action=upgrade;file=smf_patch_1.0.23_1.1.17.tar.gz;smf_version=1.1.16


Take a peek at what I'm doing! ;D




Hai bisogno di supporto in Italiano?

Aiutateci ad aiutarvi: spiegate bene il vostro problema: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.

Eclipse16V

I worked with:
SMF 2 in German

Shop:
SID Giessen

4Kstore


¡¡NEW MOD: Sparkles User Names!!!

codebirth

Quote from: emanuele on December 16, 2012, 05:27:05 PM
Quote from: DeVIL-I386 on December 16, 2012, 05:24:15 PM
Where should this option be hidden? Is it Administration Center » Maintenance » Forum Maintenance » Routine » Check all files against current versions?
Almost but not exactly: admin > maintenance > scheduled tasks > scheduled tasks
Then under the column "run now" select the box corresponding to "Fetch Simple Machines Files", and click the button "run now".

Thank you. Smooth upgrade.

Colin

Thanks for the feedback. That is what we like to hear.
"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin

Advertisement: