Simple Machines is happy to announce the release of SMF 1.1.6, which fixes a number of minor bugs in 1.1.5 and addresses a security vulnerability. While the vulnerability primarily affects SMF installations on Windows servers, we would like to encourage all users to upgrade as soon as possible. A successful exploit could result in privilege escalation.
For those users running the 1.0.x and 2.0 beta branch, we have released 1.0.14 and 2.0 beta 4 respectively, addressing the above issues.
SMF 1.0.13 users
Use the package manager to upgrade to 1.0.14. Simply visit your admin center and follow the upgrade advice on the main page. Alternatively, you can use either of the packages on the download page.
SMF 1.1.5 users
Use the package manager to upgrade to 1.1.6. Simply visit your admin center and follow the upgrade advice on the main page. Alternatively, you can use either of the packages on the download page.
SMF 2.0 beta 3, 2.0 beta 3.1 and 2.0 beta 4 (Charter Member release)
Please upgrade to SMF 2.0 beta 4 public by using the packages from the download page. (News: What Is New In SMF 2.0 Beta 4 Public (http://www.simplemachines.org/community/index.php?topic=260303.0))
If you cannot upgrade using the package manager, please follow the instructions posted in the Online Manual about installing and upgrading.
Finally - please do not use this topic for any support requests. You will get a much more prompt response by visiting the relevant support board!
Regards,
Simple Machines
For SMF 2.0 beta 3 users wondering what else is new for SMF 2.0 Beta 4 Public, please see What Is New In SMF 2.0 Beta 4 Public (http://www.simplemachines.org/community/index.php?topic=260303.0)
Congratulations!
oo beta 4
Thanks for the incredibly quick update.
Woo-hoo, SMF 2.0 Beta 4 Public FTW!!!!
WOW!! Nice work simplemachines
Whit smf 2.0 beta 4 is time to modify my theme :P
Nice to have this out at last! :D
QuoteFinally - please do not use this topic for any support requests. You will get a much more prompt response by visiting the relevant support board!
Huzzah!
just upgraded my big board (2.4 million posts) which is heavily modded from 1.1.5 to 1.1.6 using the package manager link in the admin center - and it went fantastic.
Took just a few seconds to update!
Well done guys :)
Tony
w00t!!! Just found out!!! :D
It's time for a block party!!! Bring out the beer!!! Bring out the women!!! ;)
Thanks for your hard work guys. It's great to see that SMF is becoming better and better. :)
The mod site needs to be updated so that authors can report compatibility with 1.1.6 and Beta 4
Quote from: spearfish on September 07, 2008, 07:21:41 PM
The mod site needs to be updated so that authors can report compatibility with 1.1.6 and Beta 4
Yep - and it will be... we just wanted to get this out asap :)
Will work on that now.
Very nice, thanks for all the hard work.
I'm not looking for support, but wanted to point this out.
In my Administration Center in the Live from Simple Machines... box it shows this.
SMF 1.1.6 on April 20, 2008, 09:56:14 PM
It seem to have the same time and date as when the last patch came out for SMF 1.1.5
Anyone else see this in there Administration Center or is it just me?
Probably a little typo, it'll get fixed soon. Thanks for pointing that out, ApplianceJunk!
Quote from: Tony on September 07, 2008, 07:22:42 PM
Quote from: spearfish on September 07, 2008, 07:21:41 PM
The mod site needs to be updated so that authors can report compatibility with 1.1.6 and Beta 4
Yep - and it will be... we just wanted to get this out asap :)
A couple days won't make much difference. It will take most modders that long to get familiar with 2B4 anyway. It will take a couple days before anybody upgrading to 2B4 is going to be looking for mod compatibility.
It'll probably be about an hour or two before mod support threads start filling up with the same "when will it be out?" questions. :P
By the way, I hereby Christen the new release "2-by-4" or "2x4" or "2B4." You heard that first right here and I'm the dude that named it! :D
Congratulations. upgrade was smooth and perfect. It even rectified the little top ten topic starter bug. Great job, and thanks.
Thanks :)
Just updated to 1.1.6. The installation went smoothly....BUT.....
Now when I run the "check for current versions" there are some that are different. How can that happen? That forum was installed only a week ago (switched hosts), and had 1.1.5 installed.
Quote from: spearfish on September 07, 2008, 07:21:41 PM
The mod site needs to be updated so that authors can report compatibility with 1.1.6 and Beta 4
Has been done now :)
Execute Modification ./Sources/Subs.php Test failed :(
Can't upgrade...any help?
Couple of things:
1) Check this out (http://www.demo.ericvernon.com/index.php). Here's my mod demo site, I uninstalled all mods before upgrading from Beta 3.1 to Beta 4. The both menubar and "Mark messages as read" button are messed up. You may want to look into that.
2) Is the hidden status for email addresses used on this site available in this new beta?
Well I just uninstalled all my mods on one of my 2.0b3.1 sites, uploaded the 2x4 zip file, uploaded unzip.php (suitably customized for the filename), ran repair_settings.php and noted that one of the check boxes wasn't checked but should be (forgot which), deleted repair aind install, clicked to the site and it's up!!! Total time about 10 minutes.
It's alive!!! Alive!!! :)
Awesome.
to all:
if you require support for upgrades, etc, please search the board to see if your question has already been answered, and if not please start a topic in Install and Upgrade Help (http://www.simplemachines.org/community/index.php?board=10.0)
Installation was smooth like butter. Thanks!
YAY !!!!!!!!
I'M SO HAPPY!!
:D :D :D
Great job, and thanks SimpleMachines! Congrats :D
SMF 2.0 Beta 4 FTW!! ;D
will this affect any mods installed? or if you did any changes on the default theme? cause I made a lot of changes
i just upgraded to 1.1.5....
seriously
Quote from: Shadow_KC on September 08, 2008, 01:35:06 AM
i just upgraded to 1.1.5....
seriously
Good timing... NOT! ;)
Quote from: jepot5 on September 08, 2008, 01:22:00 AM
will this affect any mods installed? or if you did any changes on the default theme? cause I made a lot of changes
Yes. Probably. You should have done like me, put your changes into mod packages.
Happy coding! :)
1.1.6 -- NO theme edits, mod compatibility should be mostly the same as 1.1.5's
2.0 Beta 4 -- MANY theme edits, mod compatibility is probably not all that great.
Thanks guys&gals, I updated from 1.1.5 to 1.1.6 without any problem.
Quote from: Deprecated on September 07, 2008, 08:02:16 PM
Well I just uninstalled all my mods on one of my 2.0b3.1 sites, uploaded the 2x4 zip file, uploaded unzip.php (suitably customized for the filename), ran repair_settings.php and noted that one of the check boxes wasn't checked but should be (forgot which), deleted repair aind install, clicked to the site and it's up!!! Total time about 10 minutes.
It's alive!!! Alive!!! :)
Thanks for the tips, I did the same thing and it was smooth!
I don't understand this:
Security.php
<search for>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</search for>
<replace>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</replace>
Aren't they same?
Good Work all
thank you
Thanks, update was successful.
Quote from: Hoochie Coochie Man on September 08, 2008, 02:38:44 AM
I don't understand this:
Security.php
<search for>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</search for>
<replace>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</replace>
Aren't they same?
It's the negative energy in the first one... the replacement has much more positive energy in it's aura.
Quote from: YodaOfDarkness on September 08, 2008, 03:17:25 AM
Quote from: Hoochie Coochie Man on September 08, 2008, 02:38:44 AM
I don't understand this:
Security.php
<search for>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</search for>
<replace>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</replace>
Aren't they same?
It's the negative energy in the first one... the replacement has much more positive energy in it's aura.
I don't understand what exactly you mean, but anyway.. if you say so..
PS: first one has many spaces at the end of the line, but second one hasn't. ıs this the change?
i keep getting this:
20. Execute Modification ./SSI.php Test failed
Quote from: Hoochie Coochie Man on September 08, 2008, 03:37:20 AM
Quote from: YodaOfDarkness on September 08, 2008, 03:17:25 AM
Quote from: Hoochie Coochie Man on September 08, 2008, 02:38:44 AM
I don't understand this:
Security.php
<search for>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</search for>
<replace>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</replace>
Aren't they same?
It's the negative energy in the first one... the replacement has much more positive energy in it's aura.
I don't understand what exactly you mean, but anyway.. if you say so..
PS: first one has many spaces at the end of the line, but second one hasn't. ıs this the change?
Yep, that's it
Its great to finally see the new release for SMF 2 Beta 4.0. :D
Updating my mods for this version should be interesting... ;)
Flawless update from 1.1.5 to 1.1.6. Thanks.
Noticed that were many files included, is there any txt with a detailed "what's new"?
Nice news! Thank you.
1.1.6 is only a minor bug and security release. basically, a "maintenance" release
details on the changes done can be found on the changelog, which you can locate conveniently on the downloads page :)
Quote from: YodaOfDarkness on September 08, 2008, 03:51:21 AM
Quote from: Hoochie Coochie Man on September 08, 2008, 03:37:20 AM
Quote from: YodaOfDarkness on September 08, 2008, 03:17:25 AM
Quote from: Hoochie Coochie Man on September 08, 2008, 02:38:44 AM
I don't understand this:
Security.php
<search for>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</search for>
<replace>
// Don't check, just free the stack number.
elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms']))
</replace>
Aren't they same?
It's the negative energy in the first one... the replacement has much more positive energy in it's aura.
I don't understand what exactly you mean, but anyway.. if you say so..
PS: first one has many spaces at the end of the line, but second one hasn't. ıs this the change?
Yep, that's it
Thanks for the information..
and thank you very much for update.
Quote from: locau on September 08, 2008, 03:44:10 AM
i keep getting this:
20. Execute Modification ./SSI.php Test failed
I have the same problem. I'm looking in the
smf_1-1-5_to_1-1-6_patch.mod but I can't seem to find the changes that are made to the SSI.php file?
Anyone has this change info?
Quote from: ApplianceJunk on September 07, 2008, 07:24:45 PM
Very nice, thanks for all the hard work.
I'm not looking for support, but wanted to point this out.
In my Administration Center in the Live from Simple Machines... box it shows this.
SMF 1.1.6 on April 20, 2008, 09:56:14 PM
It seem to have the same time and date as when the last patch came out for SMF 1.1.5
Anyone else see this in there Administration Center or is it just me?
Yeah I see the date also set as SMF 1.1.6 on 20 April , 2008, 21:56:14 PM
just a typo I would guess ;D
Thanx for the update.
Weldone once again
I've got more than 8000 users on my forum and during the updates the following query:
if (!empty($updates))
foreach ($updates as $newStatus => $members)
upgrade_query("
UPDATE {$db_prefix}members
SET is_activated = $newStatus
WHERE ID_MEMBER IN (" . implode(', ', $members) . ")
LIMIT " . count($members));
was bugging because of the number of members I've solve this problem by adding an array chunk:
if (!empty($updates))
foreach ($updates as $newStatus => $members)
{
$member = array_chunk($members,1000);
foreach($member as $mem)
{
upgrade_query("
UPDATE {$db_prefix}members
SET is_activated = $newStatus
WHERE ID_MEMBER IN (" . implode(', ', $mem) . ")
LIMIT " . count($members));
}
}
For people getting the following error :
20. Execute Modification ./SSI.php Test failed
Look in the source of the SSI.php file, and on line 8, in the comments box, the Software Version string will be something different than
* Software Version: SMF 1.1.5 *
Change this manually to this value, and than try to apply the mod again. Chances are, the error will be gone ! ;D
absolutely perfect, thank you!!
On my SMF 1.1.5 it says in the package manager:
403 Forbidden
You don't have permission to access /index.php?action=pgdownload;auto;package=http://custom.simplemachines.org/mods/downloads/smf_patch_1.0.14-1.1.6.zip;sesc=205182cdb98a1a33234bed4...... on this server.
Apache Server at overunity.com Port 80
Also when I try to download the 7.9 KB patch manually and try to upload it manually in the package manager it says:
Patch corrupted
But now I have set all files via my Hosting file manager to 777 permission and
then I could upload the patch okay and it went through okay ,
so now I have SMF 1.1.6
So watch out your file permissions, before you install it.
Regards, Stefan.
Quote from: LHVWB on September 08, 2008, 03:56:10 AM
Its great to finally see the new release for SMF 2 Beta 4.0. :D
Updating my mods for this version should be interesting... ;)
Now you understand the ancient Chinese curse, "May you lead an interesting life." ;)
Unfortunately, my Chinese friends tell me that it's not an ancient (or modern) curse at all, or at least not a Chinese one.
Quote from: Paracelsus on September 08, 2008, 04:40:13 AM
Flawless update from 1.1.5 to 1.1.6. Thanks.
Noticed that were many files included, is there any txt with a detailed "what's new"?
That would be the Changelog. You probably missed it on the download page because your eyes were magnetized to the beautiful "Beta 4" legend. ;)
http://download.simplemachines.org/index.php?thanks;filename=smf_2-0-beta4p_changelog.txt
Quote from: Hoochie Coochie Man on September 08, 2008, 03:37:20 AM
I don't understand what exactly you mean, but anyway.. if you say so..
PS: first one has many spaces at the end of the line, but second one hasn't. ıs this the change?
Yoda is exhibited his finely honed sense of humor, yet giving you the correct answer. If the only difference is spaces, then that's the reason, that coding guidelines prohibit the use of spaces and require that tabs be used instead. The edit is to conform the code to proper coding guidelines.
14. Execute Modification ./Sources/Subs.php Test failed
What do i need to fix these issues
@locau, houseofdreams, SaTaNaSDiaBoLo, houseofdreams, hartiberlin and chrisb.
You are unlikely to receive any support in this topic. Please have a read of the first post more carefully.
Quote from: Grudge on September 07, 2008, 04:45:46 AM
Finally - please do not use this topic for any support requests. You will get a much more prompt response by visiting the relevant support board!
The correct place to put support requests for upgrading is in the support board for upgrading SMF:
http://www.simplemachines.org/community/index.php?board=10.0 (http://www.simplemachines.org/community/index.php?board=147.0)
Also have a read of this documentation as well, you need to provide more information before anyone can help you:
How do I ask support questions the smart way? (http://docs.simplemachines.org/index.php?topic=494)
Not gonna get any support from me in this thread, that's for sure.
Just to state it again folks:
Post your support questions in an appropriate board. This topic is in the News and Updates board, and is totally inappropriate for support questions!!!
No support questions in this topic please!!!
I just felt compelled to pipe in on this and just THANK YOU....to SMF for patching this Vulnerability. I have a disease thats killing me, and I use my SMF to raise awareness of it...I have been with SMF from the start of my site, about 3 yrs ago.
I had No security problems, until I updated to 1.1.5 at which times, my site was hacked & destroyed....3 times in about 3 months. Until today, do I now feel the same confidence in SMF that I had in the begining :)
Again, thank you Guys/Gals....I can now rebuild again, I been waiting on this 8)
An Error Has Occurred!
The package you are trying to download or install is either corrupt or not compatible with this version of SMF.
Quote from: Tony on September 07, 2008, 07:01:43 PM
just upgraded my big board (2.4 million posts) which is heavily modded from 1.1.5 to 1.1.6 using the package manager link in the admin center - and it went fantastic.
Took just a few seconds to update!
Well done guys :)
Tony
Nope, will have to do a manual upgrade, got this error when clicking the link:
The package you are trying to download or install is either corrupt or not compatible with this version of SMF.
Oh well...
Quote from: k_talk on September 08, 2008, 11:12:11 AM
An Error Has Occurred!
The package you are trying to download or install is either corrupt or not compatible with this version of SMF.
Same here.
Oz
edit: downloaded the attachment from the first post and installed manually and worked fine.
News: SMF 1.1.5 has been released! Find out what's new!
Gonna change that any time soon? ;)
Thanks for the patch. I just updated. =)
Quote from: a2h on September 08, 2008, 09:40:04 AM
I had No security problems, until I updated to 1.1.5 at which times, my site was hacked & destroyed....3 times in about 3 months. Until today, do I now feel the same confidence in SMF that I had in the begining :)
Unless you are running on a Windows server with PHP below 5.2.6, you would not be affected by the problem being patched (well, not nearly as bad). It is present in all older versions as well (we are working around a problem with older versions of PHP, not specifically an SMF issue).
If you have been having issues with hacking attempts, you should ask your host to review the server, or you should see if you can get the raw error and access logs. If you think there is a problem in SMF itself, use the security report form located in the about section of our site.
Cool, thanks for the smooth update all! 8)
Hello,
I have a problem so far has always been my updated forum without problems, but now is not updated to version 1.1.6, and however hard they try to tell me that can not find the url
What can you do?
Greetings.
Congrats SMF for the 1.1.6 upgrade.
Tell me try it tomorrow morning and leave any comments are feedback here.
Hi, I have instal smf 1.1.5 and upgrade 1.1.6
Upgrading...
Updating and creating indexes... Unsuccessful!
This query:
ALTER TABLE *****_smileys
ORDER BY LENGTH(code) DESC;
Caused the error:
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'LENGTH(code) DESC' at line 2
Help me please.
I'll say this once more:
If you require assistance, advice, or support for the upgrade, you need to post in Install and Upgrade Help (http://www.simplemachines.org/community/index.php?board=10.0)
If you have a comment on the release, feel free to post here, however, no support shall be rendered in this topic.
Thanks!
I upgraded one forum with 100.000+ posts from 1.1.5 to 2.0 beta 4 and updated 2 medium ones from 1.1.5 to 1.1.6. Each upgrade/update went without a hitch, very smooth. Love the upgrade screen introduced in the 2.0 series :)
Congratulations to the devs and all the people involved with developing/helping out with the 2.0. Keep up the good work :)
Thank you, update successfull
Thanks! Update went very quickly and smoothly. I used to dread logging into admin and seeing a red font on my version as I always used to run into trouble on my old host with updating.
PLEASE DO NOT POST SUPPORT QUESTIONS HERE
Maybe someone will see that :)
Hmm. Nice Dziner Studio should make DS-Natural for SMF 2 and I will be able to upgrade :)
Congrats on the release. Thanks ;)
Also we should make it a bit more noticeable eh?
PLEASE DO NOT POST SUPPORT QUESTIONS HERE
err, most people who would post a support question wouldn't bother reading the fourth page... they'll 99% of the time use the Reply button right before the first post.
1.1.6 update went perfectly in microseconds. Thanks.
About two more support questions and this topic should just be closed. Maybe delete the luser's accounts too. ;)
Thank you :)
i ve just upgrade from 1.1.5 to 1.1.6
large forum and all went OK
cheers
Upgrade SMF (http://docs.simplemachines.org/index.php?board=3.0;sort=subject)
An Error Has Occurred!
The package you are trying to download or install is either corrupt or not compatible with this version of SMF.
This is the error that I get when trying to upgrade SMF in my forum.
What can I do?
Greetings.
Quote from: metallica48423 on September 08, 2008, 02:07:37 PM
I'll say this once more:
If you require assistance, advice, or support for the upgrade, you need to post in Install and Upgrade Help (http://www.simplemachines.org/community/index.php?board=10.0)
If you have a comment on the release, feel free to post here, however, no support shall be rendered in this topic.
Thanks!
And once more, metallica? ;)
I've heard people need to hear things 3 times to remember it, well maybe they need to hear it 9 in this instance.
Okay, to help people understand:
If you require assistance, advice, or support for the upgrade, you need to post in Install and Upgrade Help (http://www.simplemachines.org/community/index.php?board=10.0)
Since I know that people can't (or mostly won't) read, this topic is now locked.