• Welcome to Simple Machines Community Forum. Please login or sign up.

SMF 2.0.1 and 1.1.15 critical security patches released

Started by Norv, September 18, 2011, 06:24:43 PM

Previous topic - Next topic

maximumrock

i have version SMF 2.0 RC5 .. does this critical security patch apply to my forum?

Norv

Quote from: maximumrock on September 21, 2011, 02:46:50 PM
i have version SMF 2.0 RC5 .. does this critical security patch apply to my forum?

Yes, it does. I strongly recommend to upgrade to 2.0.1. You will need to make a large upgrade, since from RC5 to 2.0 there is no patch, only from 2.0 to 2.0.1 your forum can be upgraded with the patch. Please note that there are security weaknesses addressed in 2.0 as well, so I really recommend that you upgrade your forum, when possible.
To-do lists are for deferral. The more things you write down the later they're done... until you have 100s of lists of things you don't do.

File a security report | Developers' Blog | Bug Tracker


Also known as Norv on D* | Norv N. on G+ | Norv on Github

maximumrock

Quote from: Norv on September 21, 2011, 02:57:04 PM
Quote from: maximumrock on September 21, 2011, 02:46:50 PM
i have version SMF 2.0 RC5 .. does this critical security patch apply to my forum?

Yes, it does. I strongly recommend to upgrade to 2.0.1. You will need to make a large upgrade, since from RC5 to 2.0 there is no patch, only from 2.0 to 2.0.1 your forum can be upgraded with the patch. Please note that there are security weaknesses addressed in 2.0 as well, so I really recommend that you upgrade your forum, when possible.

Thanks! Is there a preferred way of doing this? All i have to do is apply this patch and it is upgrade or do i have to upgrade to new version from download page first.. thx again

Kindred

There is no patch file for any RC version. If you are running any RC version,,you must use the "large upgrade" pack and replace all of the files.
Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.<br /><br />"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

maximumrock

Quote from: Kindred on September 21, 2011, 03:03:30 PM
There is no patch file for any RC version. If you are running any RC version,,you must use the "large upgrade" pack and replace all of the files.

ohhhh ok.. thanks...thats what i have --> SMF 2.0 RC5

is there a tutorial on the easiest way to upgrade the forum without messing it up?

Illori

take a look at Upgrading SMF and if you have further questions please open a separate thread in the proper board.

maximumrock

Quote from: Illori on September 21, 2011, 03:06:36 PM
take a look at Upgrading SMF and if you have further questions please open a separate thread in the proper board.

will do! thanks! but upgrading for my version is recommended even though the patch isnt for mine?

Illori

yes you need to upgrade to latest version so you will have the security issues since your version was released patched. once you upgrade to 2.0.1 you do NOT need to install the patch.

Jntg4

Was the 1.0 branch updated or not this time?  I'm assuming there is no update to apply to it, right?
Free Domain Name: http://www.co.cc/?id=167358

Illori

if a version is affected by the security issue a patch will be issued otherwise they are not affected by the issue.

newtoallthis

Added to main and test forums via Package Manager apparently without a hitch.

Thanks to the SMF developers for their hard work.  8)
SMF 2.0.11
Simple Portal 2.3.3
Aeva Media 1.4c
MediaWiki 1.24.0


JeffG1

Thanks. My forum was upgraded instantaneously (so it seemed) to 2.0.1 with a couple of clicks. I notice you haven't upgraded your own forum yet.  ;D

MarkRH

Saw the notice in the 2.0 Admin Center. Backed up database and files, clicked the update link, all is well.

Thanks :)
Mark H.
Pelicar Fantasy RPG Forum using SMF 2.1 RC 2 Now (Also testing 2.1 RC 2 locally)

mextremex


ntr2ntr

Thanks a lot SMF, you have been so great u guys rockkk

Biology Forums


Illori

some security issues are fixed which is stated in the first post of this thread.


Account Abandoned


Advertisement: