Simple Machines Community Forum

Simple Machines => News and Updates => Topic started by: Oldiesmann on October 02, 2014, 07:13:55 PM

Title: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Oldiesmann on October 02, 2014, 07:13:55 PM
Dear users,

Simple Machines Forum has released security patches to both the 1.1.x and the 2.0.x release lines. This brings our released versions to SMF 1.1.20 and SMF 2.0.9.

Several security issues were identified in both release lines and have been addressed with this patch.  It is, therefore, recommended that you update your forums immediately to ensure that your community is safe.  In addition to the security patches, a few bug fixes for the SMF 2.0 line have also been included in the 2.0.9 patch.

If you are running version 2.0.8, you can update your forum to version 2.0.9 using the package manager. As usual, you should see the upgrade notification in the Admin panel and in the package manager, which will allow you to download and install the patch seamlessly.  If you don't see the notification about the update, please run the scheduled task "Fetch Simple Machines files".  You can also download the patch for 2.0.9 from the customize site (http://custom.simplemachines.org/upgrades/) by downloading the smf_patch_1.1.20_2.0.9.zip patch file, and then installing it from the package manager, like any other mod package.

If you are running 1.1.19, you can update to 1.1.20 by using the smf_patch_1.1.20_2.0.9.zip patch file and installing it via the package manager as well.  If you are still using 1.1.x branch, please be aware this will be the last patch released for this version, so you are strongly urged to upgrade to 2.0.9, in order to be able to continue to receive security upgrades to your forum. Note that we will continue to provide support for 1.1 until 2.1 final is released.

If you use older versions of SMF, you can upgrade by using the full upgrade archive for version 2.0.9 from the downloads page (http://download.simplemachines.org/). Be aware that using this upgrade method will require you to replace your mods with ones designed for the 2.0.x line

You can also view the change log for the latest release, as usual, on the downloads page (http://download.simplemachines.org/).

If you are having problems downloading the patch from the admin panel, you can download the package from the upgrade patches page (http://custom.simplemachines.org/upgrades/) and install it like a mod, as instructed above.

Please refer to the Online Manual for more details about:
* upgrading  (http://wiki.simplemachines.org/smf/Upgrading)
* patching (http://wiki.simplemachines.org/smf/Patching)

Please do not use this topic for support requests.  You will receive a much quicker and better response by posting in the relevant support board!

Thank you for using SMF! :)

Regards,
Simple Machines Forum
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Looking on October 02, 2014, 07:16:03 PM
Thanks for keeping us up to date!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: ApplianceJunk on October 02, 2014, 07:20:29 PM
Thanks
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: ARG01 on October 02, 2014, 08:04:53 PM
Appreciated.  ;)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Illori on October 02, 2014, 08:15:56 PM
Quote from: SimpMode on October 02, 2014, 08:04:53 PM
Appreciated.  But where is the 2.0.9 patch download? The Upgrade Downloads page only supplies up to 2.0.8. ;)

it is on the bottom of the list.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: ARG01 on October 02, 2014, 08:17:28 PM
LOL. I just noticed that.  ;D
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: SaltedWeb on October 02, 2014, 08:40:35 PM
No issues works well, thank you.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: KVL on October 02, 2014, 09:09:25 PM
Updated is successfully. :) Thank you very much SMF team for your very great job! :)

Many thanks to SMF! :)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: vbgamer45 on October 02, 2014, 09:10:38 PM
Congrats on the release! Thanks for update to SMF 1.1.x as well
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Mstcool on October 02, 2014, 09:43:29 PM
Woot Woot! :D
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: forumdraco on October 03, 2014, 03:34:41 AM
Strange, on one forum I see the 2.0.9 in the Administration Center and I can upgrade using the package manager, on another forum it says 2.0.8 is the latest release... any idea how this is possible?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: ThomasJones on October 03, 2014, 04:05:06 AM
Really nice work guys ~ will update when I get to work  :D
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: tandro on October 03, 2014, 04:18:31 AM

Many thanks to SMF Team for keeping us up to date! !!!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Fisch.666 on October 03, 2014, 04:31:30 AM
Hi,

when checking for newer files in the board maintenance the Subs-Post.php is shown as "my version 2.0.8" and the "current version 2.0.9" when applying the patch via the package manager. Seems the header @version 2.0.8 was not updated by the patch.

Quote from: forumdraco on October 03, 2014, 03:34:41 AM
Strange, on one forum I see the 2.0.9 in the Administration Center and I can upgrade using the package manager, on another forum it says 2.0.8 is the latest release... any idea how this is possible?

You need to run the Task "fetch simple machines data" in your planned tasks (maintenance)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Herman's Mixen on October 03, 2014, 04:45:00 AM
Not all files are patched only the security ones wich needed to be patched ;)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Fisch.666 on October 03, 2014, 04:52:03 AM
Hi,

the Subs-Posts.php was patched in the smf_2-0-9_patch.xml or am i wrong?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: margarett on October 03, 2014, 05:05:34 AM
Subs-Post.php (no "s") was.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Fisch.666 on October 03, 2014, 05:22:26 AM
Ok, so probably just the header wasn't update. Have now done this manually
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: forumdraco on October 03, 2014, 05:44:34 AM
Quote from: Fisch.666 on October 03, 2014, 04:31:30 AM
Quote from: forumdraco on October 03, 2014, 03:34:41 AM
Strange, on one forum I see the 2.0.9 in the Administration Center and I can upgrade using the package manager, on another forum it says 2.0.8 is the latest release... any idea how this is possible?

You need to run the Task "fetch simple machines data" in your planned tasks (maintenance)

Thanks, that did the trick! ;-)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Mr.Truckman on October 03, 2014, 08:04:01 AM
Thanks  ;D
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Masterd on October 03, 2014, 10:00:33 AM
Good job boys and girls!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Steve on October 03, 2014, 11:12:01 AM
Add my thanks to everyone involved. :D
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Apllicmz on October 03, 2014, 11:46:31 AM
Yes good work
thank you
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Robert. on October 03, 2014, 12:05:37 PM
Congrats!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Mr. Jinx on October 03, 2014, 12:51:45 PM
Thanks again for keeping SMF secure and bug free!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: NekoJonez on October 03, 2014, 02:43:50 PM
When can we see the upgrade package?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 03, 2014, 02:44:56 PM
The upgrade package is there...
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: NekoJonez on October 03, 2014, 02:49:07 PM
Forgive me. :P

(Blame it on being tired of being a receptionist at a busy busy company all week.)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Ninja ZX-10RR on October 03, 2014, 03:54:42 PM
Thanks for the update :)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Aaron10 on October 03, 2014, 05:25:01 PM
Just updated without errors but before updating I noticed the latest version was stuck at ?? and the news area says:

QuoteYou are unable to connect to simplemachines.org's latest news file.

This mustve just started happening recently as I've just noticed it. :S
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Herman's Mixen on October 03, 2014, 08:59:36 PM
Quotetry
to run the Task "fetch simple machines data"

does that help ?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Aaron10 on October 03, 2014, 11:23:32 PM
Admin > Scheduled Tasks > Fetch Simple Machines Files (Run Now)? Yeah I tried it but still nothing.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: mashby on October 03, 2014, 11:33:38 PM
Of course this topic is not for support and the site in your signature is on 2.0.9. If you are having issues on another site, use the 2.0.x Support board please. :)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Abhijit1030 on October 04, 2014, 02:20:48 AM
I think IMG tag not working in SMF 2.0.9

I tried to put image a post with IMG tag but image not showing.

I notice it also in my forum.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Ninja ZX-10RR on October 04, 2014, 02:30:35 AM
This topic is not for support, once again.

The IMG tag works perfectly both here and on my 2.0.9 anyway so it must be something on your own forum, please post in the support board, so that someone may assist you :)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Abhijit1030 on October 04, 2014, 02:38:27 AM
Quote from: ♦ Ninja ZX-10RR ♦ on October 04, 2014, 02:30:35 AM
This topic is not for support, once again.

The IMG tag works perfectly both here and on my 2.0.9 anyway so it must be something on your own forum, please post in the support board, so that someone may assist you :)

sorry for that see this topic I created image not showing with IMG tag
http://www.simplemachines.org/community/index.php?topic=528506.0
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Antechinus on October 04, 2014, 02:44:14 AM
QuoteIf you are still using 1.1.x branch, please be aware this will be the last patch released for this version, so you are strongly urged to upgrade to 2.0.9, in order to be able to continue to receive security upgrades to your forum. Note that we will continue to provide support for 1.1 until 2.1 final is released.

Interesting. So what you are saying is that 2.1 final is going to be released before any new exploits are found for 1.1.x. That would imply that 2.1 final is almost ready. :D

That must be the fastest beta and RC series in history.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Masterd on October 04, 2014, 05:00:48 AM
Quote from: Antechinus on October 04, 2014, 02:44:14 AM
Interesting. So what you are saying is that 2.1 final is going to be released before any new exploits are found for 1.1.x. That would imply that 2.1 final is almost ready. :D

That must be the fastest beta and RC series in history.

I was wondering the same thing. However, it does partialy make sense to completely shift focus from 1.1 and put every spare second into 2.1.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Antechinus on October 04, 2014, 05:08:48 AM
They'll probably get away with it, given that exploits for 1.1.x don't seem to be turning up very often, but "we will continue to provide support for 1.1 until 2.1 final" implies 1.1.x will be patched if exploits turn up before 2.1 is ready. If it's not going to be patched any more, then in reality it is unsupported now.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Masterd on October 04, 2014, 05:17:27 AM
Quote from: Antechinus on October 04, 2014, 05:08:48 AM
They'll probably get away with it, given that exploits for 1.1.x don't seem to be turning up very often, but "we will continue to provide support for 1.1 until 2.1 final" implies 1.1.x will be patched if exploits turn up before 2.1 is ready. If it's not going to be patched any more, then in reality it is unsupported now.

They're probably reffering to the support board.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Antechinus on October 04, 2014, 05:24:03 AM
That doesn't fix security problems. ;)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: amiralib on October 04, 2014, 06:18:22 AM
does this patch fix the no UTF8 websites problems with PHP 5.4 or not?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 04, 2014, 08:00:55 AM
Did you read the changeLog?

And antechinus...
We will continue to provide support in the support boards... However, we will not be patching 1.1.x any further.  From now on, The recommended solution to security issues in 1.1.x is to upgrade to 2.0.x....
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: NekoJonez on October 04, 2014, 08:07:11 AM
Quick question: Which of the files are extremely important to update? Since some get for me: "Test failed (ignore errors)".

What do these parts of the update do exactly...? Is it really wise to ignore them?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 04, 2014, 08:08:10 AM
Your questions has alreayd been answered, above in this same thread...
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: gisfreak on October 04, 2014, 10:32:22 AM
congrats, updating now
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: medicMe on October 04, 2014, 11:48:11 AM
 :)

Thanks for all the hard work!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: HDB on October 04, 2014, 02:40:36 PM
2.0.9 Patch installed on two forums and all is working great! Thanks!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Chalky on October 04, 2014, 03:00:55 PM
Nice work guys, thank you!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Antechinus on October 04, 2014, 05:15:39 PM
Quote from: Kindred on October 04, 2014, 08:00:55 AM
Did you read the changeLog?

And antechinus...
We will continue to provide support in the support boards... However, we will not be patching 1.1.x any further.  From now on, The recommended solution to security issues in 1.1.x is to upgrade to 2.0.x....

Ok, so let's be clear on this. The no-BS version is that in terms of security, 1.1.x is unsupported as of now. This is a change of policy over what has consistenly been claimed for years; that 1.1.x would be patched until 2.1 was stable.

That means that if an exploit for 1.1.x turns up before 2.1 is stable, which is quite possible given the pace of SMF dev, the admin of any 1.1.x site will have to turn their site upside down with a major upgrade to 2.0.x. Then, when 2.1 is stable, they will have to do it all over again if they want something up to date. 2.0.x isn't all that impressive by today's standards, and IMO has little real advantage over a well-customised 1.1.x, so this is going to be annoying. It'd be much better to just be able to go straight to 2.1, and only turn the site upside down once.

Do note that there are already other forum apps, some forked from SMF and some not,  that are stable now, and have very good features, and very good migration tools. If I was still adminning a 1.1.x site, I would not be taking this announcement as an incentive to upgrade to 2.0.x, because frankly there are better options available. I would be looking at those options instead. OTOH, if I could be sure of having 1.1x patched until 2.1 is stable, I would probably be more inclined to wait for 2.1.

Bottom line is you may be shooting yourselves in the foot with this change of policy. My 2c.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Antes on October 04, 2014, 05:57:28 PM
Quote from: Antechinus on October 04, 2014, 05:15:39 PM
Quote from: Kindred on October 04, 2014, 08:00:55 AM
Did you read the changeLog?

And antechinus...
We will continue to provide support in the support boards... However, we will not be patching 1.1.x any further.  From now on, The recommended solution to security issues in 1.1.x is to upgrade to 2.0.x....

Ok, so let's be clear on this. The no-BS version is that in terms of security, 1.1.x is unsupported as of now. This is a change of policy over what has consistenly been claimed for years; that 1.1.x would be patched until 2.1 was stable.

That means that if an exploit for 1.1.x turns up before 2.1 is stable, which is quite possible given the pace of SMF dev, the admin of any 1.1.x site will have to turn their site upside down with a major upgrade to 2.0.x. Then, when 2.1 is stable, they will have to do it all over again if they want something up to date. 2.0.x isn't all that impressive by today's standards, and IMO has little real advantage over a well-customised 1.1.x, so this is going to be annoying. It'd be much better to just be able to go straight to 2.1, and only turn the site upside down once.

Do note that there are already other forum apps, some forked from SMF and some not,  that are stable now, and have very good features, and very good migration tools. If I was still adminning a 1.1.x site, I would not be taking this announcement as an incentive to upgrade to 2.0.x, because frankly there are better options available. I would be looking at those options instead. OTOH, if I could be sure of having 1.1x patched until 2.1 is stable, I would probably be more inclined to wait for 2.1.

Bottom line is you may be shooting yourselves in the foot with this change of policy. My 2c.

if some admins rather to stay on 1.1.x (which you need to downgrade your php/mysql for complete compatibility) they already "be shooting themselves in the foot"... But I agree, comparing 2.1 vs 2.0 - there is a big difference and yet its worth to wait for it, rather than going another software. To me I actually asked team to kill SMF 1.1 nearly 1 year ago, but we'll see things after first two beta releases of SMF 2.1.

Quote from: ♦ Ninja ZX-10RR ♦ on October 04, 2014, 05:41:06 PM
@antechinus


I totally agree with you. I will stick to 2.0.9 until 2.1 will have the 110+ mods that I want updated, and since this is not likely to happen in at least 10 years time I think I will upgrade directly to 3, in said time, when mods etc etc... I think you got that.

Illogical


I wasn't going to reply to this topic but I don't have permission to split it so, admins will split this topic soon. This topic is not for discussing other softwares/new version or problems.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Antechinus on October 04, 2014, 06:01:20 PM
Quote from: Antes on October 04, 2014, 05:57:28 PMif some admins rather to stay on 1.1.x (which you need to downgrade your php/mysql for complete compatibility) they already "be shooting themselves in the foot"... But I agree, comparing 2.1 vs 2.0 - there is a big difference and yet its worth to wait for it, rather than going another software. To me I actually asked team to kill SMF 1.1 nearly 1 year ago, but we'll see things after first two beta releases of SMF 2.1.

Nope, because many good hosts run 1.1.x just fine. No problems at all. No downgrade required.


QuoteI wasn't going to reply to this topic but I don't have permission to split it so, admins will split this topic soon. This topic is not for discussing other softwares/new version or problems.

Well, split away if you like, but these are valid points to raise IMO, and they are directly related to the content of the OP of this topic. Just don't hide it all if you do split it.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on October 04, 2014, 07:12:33 PM
Wrong on your last point.

Any host that upgrades to PHP 5.4 or beyond - you know, for the *supported* versions of PHP (PHP 5.3 is EOL)... will have problems with SMF 1.1.

Any host that upgrades to PHP 5.5 or beyond - for the 'current' stable version of PHP - will definitely have problems with SMF 1.1.

The changes are sufficient that it is not feasible to patch such things.

And it has been recommended for months and months to upgrade anyway.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Biology Forums on October 04, 2014, 07:37:18 PM
Quote from: vbgamer45 on October 02, 2014, 09:10:38 PM
Congrats on the release! Thanks for update to SMF 1.1.x as well

Same.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Antechinus on October 04, 2014, 08:01:03 PM
Quote from: Arantor on October 04, 2014, 07:12:33 PM
Wrong on your last point.

Any host that upgrades to PHP 5.4 or beyond - you know, for the *supported* versions of PHP (PHP 5.3 is EOL)... will have problems with SMF 1.1.

Any host that upgrades to PHP 5.5 or beyond - for the 'current' stable version of PHP - will definitely have problems with SMF 1.1.

The changes are sufficient that it is not feasible to patch such things.

And it has been recommended for months and months to upgrade anyway.

Ok, so what you are saying is that 1.1.x is effectively EOL right now, and 2.1 has no ETA. So, for anyone still on 1.1.x it comes down to comparing 2.0.x against whatever else is available right now, then deciding which option they prefer.

BTW, it has been recommended to upgrade to 2.0.x since the day it went stable, so you can't really blame people for ignoring more recent exhortations without the above information being given.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on October 04, 2014, 08:07:57 PM
Me? I don't get a say on it, I'm not team :P I'm merely observing the state of play with 1.1 and current PHP versions.

The fact that the codebase is even more legacy and convoluted in places than 2.0 is, the fact that there are likely more security holes simply never discovered thus far...

Let me put it this way: the original vulnerability fixed in 2.0.9 with the package manager was found by me. Recently, in fact, as in this year. Except it's been there since the start. Who knows how many more are waiting to be found? And worse: how many of them cannot meaningfully be fixed in 1.1 because of technical restrictions?

I am surprised, though, at the outright declaration of 'no more patches'. I thought the plan was to be blunt and say 'here's 2.1 beta; officially hereby be notified that with 2.1 final which is coming soon, 1.1 will no longer be supported'.

The fact 1.1 is now 8 1/2 years old is a minor detail.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Antechinus on October 04, 2014, 08:51:48 PM
My understanding was that the policy was always to patch whatever could be patched in 1.1.x, up until the day that 2.1 was stable, at which point 1.1.x would immediately get canned completely.

But 2.1 is not currently relevant, since it has no ETA.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on October 04, 2014, 08:58:21 PM
That was my understanding too - with the caveat that with 2.1 beta 1, there would be some prominent 'yo folks, this is what we're doing, time to get your house in order' warning about 1.1's imminent sunset.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 04, 2014, 09:04:17 PM
First...  Yes, that WAS the "policy".  We have since reviewed and revised it given the difficulty in maintaining a code base which is so outdated and can't even support several of the patches to keep up with current versions of server softwares. Additionally, it is time for people to consider upgrading sooner rather than later, because of that, amongst other things.

Second...  2.1 actually does have an ETA. Such a date has just not been released to the public, per our normal policy of not declaring dates.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Ferny on October 05, 2014, 04:48:48 AM
Hello!

I think there is something wrong in the upgrade package from 2.0.8 to 2.0.9. It's about the second operation in "$sourcedir/ManageServer.php":

<operation>
<search position="before"><![CDATA[
$context['config_vars'][$config_var[1]]['value'] = unserialize($context['config_vars'][$config_var[1]]['value']);
]]></search>
<add><![CDATA[
$context['config_vars'][$config_var[1]]['value'] = !empty($context['config_vars'][$config_var[1]]['value']) ? unserialize($context['config_vars'][$config_var[1]]['value']) : array();
]]></add>
</operation>


It should be position="replace" instead of position="before", right? I saw some errors in the log after upgrading (I can explain the details if necessary), and after manual fixing they are gone.

That file is OK in the install and upgrade full packages for 2.0.9 (just the upgrade package is wrong).

Regards :)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Chalky on October 05, 2014, 06:39:49 AM
I don't have any errors in my log after using the patch.  What are the exact errors you're getting?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Masterd on October 05, 2014, 07:05:00 AM
Quote from: Antechinus on October 04, 2014, 08:51:48 PM
My understanding was that the policy was always to patch whatever could be patched in 1.1.x, up until the day that 2.1 was stable, at which point 1.1.x would immediately get canned completely.

I personally can't understand thier decision to support 1.1.x for so long. If they had dropped support for it back in 2012 vast mojority of (if not all) users would already be on 2.0.x and we wouldn't be in such mess.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Burke ♞ Knight on October 05, 2014, 07:11:20 AM
Quote from: Chalky on October 05, 2014, 06:39:49 AM
I don't have any errors in my log after using the patch.  What are the exact errors you're getting?

It does not actually make an error, but it does seem that an add after was used instead of a replace.
So technically, instead of replacing the line, it left it and added the newer line that had more code to it.
Thus, leaving extra code that is not needed, and may produce errors that I am unaware of at this time.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 05, 2014, 07:58:56 AM
Quote from: Ferny on October 05, 2014, 04:48:48 AM
I think there is something wrong in the upgrade package from 2.0.8 to 2.0.9. It's about the second operation in "$sourcedir/ManageServer.

Since this thread is not for support, please raise your issue in the support or bug reports boards...
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: a10 on October 05, 2014, 10:07:20 AM
Installed in seconds. Thanks.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Weirdo on October 05, 2014, 10:18:33 AM
Awesome. :)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Ferny on October 05, 2014, 01:03:07 PM
Quote from: Kindred on October 05, 2014, 07:58:56 AM
Quote from: Ferny on October 05, 2014, 04:48:48 AM
I think there is something wrong in the upgrade package from 2.0.8 to 2.0.9. It's about the second operation in "$sourcedir/ManageServer.

Since this thread is not for support, please raise your issue in the support or bug reports boards...

Posted here, with more details: http://www.simplemachines.org/community/index.php?topic=528577.0
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Oldiesmann on October 05, 2014, 01:42:21 PM
That should indeed be a replace. Just remove the original line and keep the new one there.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Ferny on October 05, 2014, 02:09:23 PM
Quote from: Oldiesmann on October 05, 2014, 01:42:21 PM
That should indeed be a replace. Just remove the original line and keep the new one there.

That's what I did ;) Another option is to replace the ManageServer.php by the one in the full-install package of 2.0.9
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Rob Lightbody on October 06, 2014, 02:07:13 PM
Thank you! :)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Biology Forums on October 06, 2014, 02:51:20 PM
I believe previews in Firefox are hanging. Any clue?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Masterd on October 06, 2014, 02:53:50 PM
Quote from: Shuban on October 06, 2014, 02:51:20 PM
I believe previews in Firefox are hanging. Any clue?

What exactly are you talking about?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Biology Forums on October 06, 2014, 02:54:48 PM
Quote from: Masterd on October 06, 2014, 02:53:50 PM
Quote from: Shuban on October 06, 2014, 02:51:20 PM
I believe previews in Firefox are hanging. Any clue?

What exactly are you talking about?

Make a post in 1.x and click preview before posting. It hangs and on Chrome is reloads the whole page.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Burke ♞ Knight on October 06, 2014, 03:04:38 PM
Quote from: Kindred on October 05, 2014, 07:58:56 AM
Since this thread is not for support, please raise your issue in the support or bug reports boards...

I think one may have already been made for this issue. ;)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: vbgamer45 on October 06, 2014, 04:10:28 PM
Quote from: Shuban on October 06, 2014, 02:54:48 PM
Quote from: Masterd on October 06, 2014, 02:53:50 PM
Quote from: Shuban on October 06, 2014, 02:51:20 PM
I believe previews in Firefox are hanging. Any clue?

What exactly are you talking about?

Make a post in 1.x and click preview before posting. It hangs and on Chrome is reloads the whole page.
Have a post on it at http://www.simplemachines.org/community/index.php?topic=528614.0
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Colin on October 06, 2014, 05:46:32 PM
Thanks folks.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: rentner on October 07, 2014, 05:11:02 AM
Thanks for the update, as always easy installation  8)

Subs-Post.php was shown in the version check 2.08 and red marked. I have changed it manualy to 2.09.
Hope it is OK

Many thanks
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: biggboss8 on October 07, 2014, 05:21:16 AM
Thanks for updating :D
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: rentner on October 07, 2014, 08:33:07 AM
Just I got problems with some mods, after installing the update 2.0.9.
Following mods are not function anymore:
- Arcade games
- Aeva
- tapatalk --> get it funcion again after reinstall

As I try to reinstall Arcade and Aeva, the forum is break down and I have to restore the forum.
Hope I get it working again.


Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: scimmiotto on October 10, 2014, 04:09:23 PM
thanks!!!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Ned.net on October 10, 2014, 05:53:33 PM
Upgraded my 5 forums in 3 clicks each : many thanks for all your work and the ease to have access to it.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 10, 2014, 06:14:59 PM
Quote from: rentner on October 07, 2014, 08:33:07 AM
Just I got problems with some mods, after installing the update 2.0.9.
Following mods are not function anymore:
- Arcade games
- Aeva
- tapatalk --> get it funcion again after reinstall

As I try to reinstall Arcade and Aeva, the forum is break down and I have to restore the forum.
Hope I get it working again.




Quote from: Kindred on October 05, 2014, 07:58:56 AM
Since this thread is not for support, please raise your issue in the support boards...
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: gogotha on October 10, 2014, 11:16:25 PM
Thank you Arantor, emanuele, Antes, fun4us, NanoSector, Suki, Chainy and SMF team for your time to make this software awesome!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: The Domain Shop on October 13, 2014, 03:55:20 PM
Thanks!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: 420SA on October 14, 2014, 02:07:01 AM
When I click to install the patch in the package manager I get ERROR 403 - FORBIDDEN

Why does this occur?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 14, 2014, 06:17:44 AM
Because your host has screwed up the server configuration, probably,,,   However...    This thread is not for support.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Steve on October 14, 2014, 09:40:07 AM
Quote from: Kindred on October 14, 2014, 06:17:44 AMThis thread is not for support.

I was curious (and bored) so I looked back to see how many times this was said. It was surprisingly less than I thought ... only five times.

I guess peeples don't get it. :P
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on October 16, 2014, 02:01:47 PM
Quote from: Steve on October 14, 2014, 09:40:07 AM
I guess peeples don't get it. :P

Like always. I've never understood why these aren't just locked as soon as they are posted.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Oldiesmann on October 17, 2014, 01:50:50 PM
Quote from: Arantor on October 16, 2014, 02:01:47 PM
Quote from: Steve on October 14, 2014, 09:40:07 AM
I guess peeples don't get it. :P

Like always. I've never understood why these aren't just locked as soon as they are posted.

How else do you expect people to show us their undying love and gratitude for our hard work? :P
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Steve on October 17, 2014, 03:40:55 PM
I was torn between that and Arantor's opinion. :D
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: koutb123 on October 17, 2014, 08:39:44 PM
Many thanks to SMF Team for keeping us up to date! !!!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on October 17, 2014, 08:42:34 PM
Quote from: Steve on October 17, 2014, 03:40:55 PM
I was torn between that and Arantor's opinion. :D

Always assume I am right until the universe says anything to the contrary ;D
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 17, 2014, 08:44:33 PM
Hey, I know that I am large, but I am not universe sized, yet...  :P
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on October 17, 2014, 08:50:51 PM
:P ;D

Here I am, brain the size of a planet, and they ask me to pick up that piece of paper. Call that job satisfaction? 'Cause I don't.

(Yes, I channel Marvin *so* well.)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Steve on October 17, 2014, 09:51:07 PM
Quote from: Arantor on October 17, 2014, 08:42:34 PMAlways assume I am right until the universe says anything to the contrary ;D

Roger that. :P


*I wonder if anyone else got the HGTTG reference ...
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 18, 2014, 12:38:50 AM
Of course we did...  Silly boy. ;)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on October 18, 2014, 01:34:57 AM
Perhaps I need to make MarvinBot come here too.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on October 18, 2014, 02:28:02 AM
Marvin is God
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on October 18, 2014, 02:31:43 AM
Not according to So Long And Thanks For All The Fish, he's not.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Masterd on October 18, 2014, 08:44:39 AM
Quote from: Arantor on October 17, 2014, 08:50:51 PM
:P ;D

Here I am, brain the size of a planet, and they ask me to pick up that piece of paper. Call that job satisfaction? 'Cause I don't.

(Yes, I channel Marvin *so* well.)

Ever heard of egoism?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on October 18, 2014, 08:53:34 AM
You do realise that Marvin describes so himself as a manically depressed android, right?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Steve on October 18, 2014, 09:10:00 AM
Quote from: Kindred on October 18, 2014, 12:38:50 AM
Of course we did...  Silly boy. ;)

Lol ... don't know you guys well enough yet to know these things. :P
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: RUKZANYA on October 24, 2014, 11:56:17 AM
Thanks...
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: s3cc0 on October 29, 2014, 08:47:49 AM
Update install went fine. Thank you.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: IamTheBoy on October 30, 2014, 03:08:25 PM
Update to 2.09 went well with no dramas here, thanks SMF devs :)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kenny01 on November 01, 2014, 09:36:41 AM
Done,
I never received any upgrade notification email as usual?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: NekoJonez on November 01, 2014, 01:30:12 PM
I never got that. I always see that in my admin panel.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on November 01, 2014, 01:43:33 PM
The last few haven't been sent for various reasons.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: ModelBoatMayhem on November 01, 2014, 02:40:15 PM
 
No email here either, have I turned something off?
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: margarett on November 01, 2014, 02:42:11 PM
Quote from: Arantor on November 01, 2014, 01:43:33 PM
The last few haven't been sent for various reasons.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: kanzay on November 23, 2014, 12:31:17 PM
thank you very much. I use this forum system at my site www.meslekciyiz.com/forum and I like this forum system.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: NekoJonez on December 16, 2014, 04:25:52 PM
So, I heard that SMF 2.0.10 is confirmed.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: margarett on December 16, 2014, 04:33:17 PM
Careful, you might be allucinating ;D
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Burke ♞ Knight on December 16, 2014, 04:40:07 PM
A possible update is always talked about, and ideas as to what goes into one if it is made.
There's always going to be ideas for adding to future updates, whether or not they do, is another story.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on December 16, 2014, 05:23:10 PM
2.0.10 is confirmed as in "It will probably be released, some time in the future, when there is a new security update required."

Until that time, no... there is no "confirmation" of 2.0.10 other than your imagination.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: dekoffieboer on December 25, 2014, 12:11:33 AM
Great Forum you guys. Keep up the good work. /happy :)
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: topogio on January 03, 2015, 04:56:53 PM
great job, but I wanted to point something out about a typo in  ./Sources/Memberlist.php

The typo was introduced in SMF2.0.8 update and was not fixed during SMF2.0.9

$serach_fields[] = 'email';

$condition = allowedTo('moderate_forum') ? '' : ')';


Which of course should have been

$search_fields[] = 'email';

$condition = allowedTo('moderate_forum') ? '' : ')';


Thanks for the great cms and the great forum, lots of hard work and greatly appreciated.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Arantor on January 03, 2015, 04:59:09 PM
The typo in 2.0.8 was only present for a short period of time and was fixed in the mainstream 2.0.8 patch.

And 2.0.9 does include a fix if the damaged 2.0.8 code was found as per http://custom.simplemachines.org/upgrades/index.php?action=upgrade;file=smf_patch_1.1.20_2.0.9.zip;smf_version=2.0.8
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: w0kie on January 23, 2015, 07:39:34 PM
1.1.20 killed the message preview function.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Kindred on January 23, 2015, 09:15:02 PM
Yes. We know.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: s1rabiulislam on March 09, 2015, 11:26:26 AM
Thanks for keeping us up to date!
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: Michelle m on March 14, 2015, 11:55:03 PM
thank you so much ..........
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: hbgmysite on March 29, 2015, 10:43:02 PM
Thanks alot
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: ngocbao on March 30, 2015, 06:23:39 AM
Thank you for giving me this message
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: GaziSalahuddin on April 04, 2015, 03:30:44 AM
Thank you very much. Great job. A possible update is always justified, and ideas as to what goes into one if it is made. There's always ideas for adding to future updates, whether or not they do, is another matter.
Title: Re: SMF 2.0.9 / 1.1.20 Security Patches Released
Post by: ismail11 on April 05, 2015, 01:18:48 AM
OK Thanks......