Advertisement:

Author Topic: SMF 2.0.1 and 1.1.15 critical security patches released  (Read 2508603 times)

Offline Illori

  • Project Manager
  • SMF Legend
  • *
  • Posts: 51,133
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #140 on: September 29, 2011, 07:07:18 AM »
please start a thread in the proper support board, this thread is not for support.

Offline Gary

  • Sorceress's Knight
  • Customizer
  • SMF Super Hero
  • *
  • Posts: 18,100
  • Gender: Male
  • So this is the luck of the draw...
    • Gazmanafc on Facebook
    • garygadsdon on LinkedIn
    • @Gazmanafc on Twitter
    • The Bongo Comics Fan Forum
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #141 on: September 29, 2011, 09:49:47 AM »
Im using smf on my host resellerspanel.com

The forum I found on there: http://forum.resellerspanel.com is running vBulletin. We can't help you there. But I'll assume you're one of their customers.

In which case, create a separate topic, linking to your own site, listing which version of SMF you're going to and from. If you're going from 1.1 to 2.0 you need to use the LARGE upgrade package which can not be run in the package manager.
Gary M. Gadsdon
Do NOT PM me unless I say so

War of the Simpsons
Bongo Comics Fan Forum
Youtube Let's Plays

^ YT is changing monetisation policy, help reach 1000 sub threshold.

Offline Weatherservice

  • Semi-Newbie
  • *
  • Posts: 79
    • WeatherService
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #142 on: October 05, 2011, 10:32:26 AM »
Thanks for the update!

Unique weathercapture: check www.weatherservice.be

Offline cicero costa

  • Newbie
  • *
  • Posts: 4
  • Gender: Male
    • www.terra-brasilis.org
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #143 on: October 07, 2011, 05:55:38 PM »
Great work, team! Congratulations!
Thank You !!!
hxxp:www.terra-brasilis.org [nonactive]

Offline Clara Listensprechen

  • Jr. Member
  • **
  • Posts: 256
  • Gender: Female
  • Impossible Person
    • clara.listensprechen on Facebook
    • @ClaraListenspre on Twitter
    • Clara's Cranny blog
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #144 on: October 10, 2011, 11:20:14 AM »
Note to SMF 2.0 users...

If this isn't showing up in your admin center, you have a couple of options:
Download it from the Upgrades Site and install it through the package manager...
...and get beyond the error message that the file is corrupt or empty how, exactly? (the usual method has been to unpack the zip on own computer and then copy over the old files, so if there's a different method I'd like to hear it)
Quote
Run the "Fetch Simple Machines Files" scheduled task as follows:
Admin -> Maintenance -> Scheduled Tasks
Check the box in the "Run Now" column next to "Fetch Simple Machines Files"
Click the "Run Now" button
I did that and it didn't. Hmmmm.
I shall continue to be an impossible person so long as those who are now possible remain possible. {Michael Bakunin 1814-1876}

Offline Illori

  • Project Manager
  • SMF Legend
  • *
  • Posts: 51,133
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #145 on: October 10, 2011, 11:21:21 AM »
please start a thread in the proper support board, this thread is not for support.

Offline Clara Listensprechen

  • Jr. Member
  • **
  • Posts: 256
  • Gender: Female
  • Impossible Person
    • clara.listensprechen on Facebook
    • @ClaraListenspre on Twitter
    • Clara's Cranny blog
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #146 on: October 10, 2011, 11:29:42 AM »
i told you i dont wanna do the upgrade via the package manager but by uploading the files normally

Upgrading through the package manager is the only way you can do it without losing existing mods.
Well, then, I'm up the creek without a paddle because my Package Manager claims that the package is either empty or corrupt. Help?
I shall continue to be an impossible person so long as those who are now possible remain possible. {Michael Bakunin 1814-1876}

Offline Illori

  • Project Manager
  • SMF Legend
  • *
  • Posts: 51,133
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #147 on: October 10, 2011, 11:30:47 AM »
please start a thread in the proper support board, this thread is not for support.

Offline Clara Listensprechen

  • Jr. Member
  • **
  • Posts: 256
  • Gender: Female
  • Impossible Person
    • clara.listensprechen on Facebook
    • @ClaraListenspre on Twitter
    • Clara's Cranny blog
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #148 on: October 10, 2011, 11:36:21 AM »
Directions given in this thread are faulty and that needs to be pointed out to whomever else may be misled by them. Correcting the faulty information in this thread is in order.  Thank you.
I shall continue to be an impossible person so long as those who are now possible remain possible. {Michael Bakunin 1814-1876}

Offline Illori

  • Project Manager
  • SMF Legend
  • *
  • Posts: 51,133
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #149 on: October 10, 2011, 11:38:45 AM »
it is not faulty it works just fine, and has been tested by many users that have upgraded their forums with no problems.

Offline Aleksi "Lex" Kilpinen

  • A Peculiar Finn
  • Lead Support Specialist
  • SMF Super Hero
  • *
  • Posts: 18,540
  • Gender: Male
  • Don't worry, I'm n00b friendly
    • Aleksi.Kilpinen on Facebook
    • LexArma on GitHub
    • aleksi-kilpinen on LinkedIn
    • There's No Place Like 127.0.0.1
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #150 on: October 10, 2011, 12:25:11 PM »
i told you i dont wanna do the upgrade via the package manager but by uploading the files normally

Upgrading through the package manager is the only way you can do it without losing existing mods.
Well, then, I'm up the creek without a paddle because my Package Manager claims that the package is either empty or corrupt. Help?

Package manager update for 2.0 -> 2.0.1 http://custom.simplemachines.org/mods/downloads/smf_patch_2.0.1.tar.gz
Package manager update for 1.1.14 -> 1.1.15 http://custom.simplemachines.org/mods/downloads/smf_patch_1.1.15.tar.gz

Manual update instructions and the Package manager update patches are found at http://custom.simplemachines.org/upgrades/
A Finnish Support Specialist
 Happily running multiple SMF 2.0 installations.
  Fooling around with an i7 990X @ 3,47Ghz / 12Gb / Win 10 x64 / 3840x2160


How you can help SMF

"Before you allow people access to your forum, especially in an administrative position, you must be aware that that person can seriously damage your forum.
 Therefore, you should only allow people that you trust, implicitly, to have such access." -Douglas

kat

  • Guest
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #151 on: October 10, 2011, 12:29:16 PM »
Ahem...

Clara, I had the same problem that you had.

I know not why, nor do I know how to fix it.

BUT (And I think this should go in the documentation, too. I'm about to attempt to do that.), there's an easy way around it, you'll be pleased to know.

Get the upgrade archive/package and upload it, STILL ARCHIVED, into your Packages directory, using your FTP client.

Then, go to Package manager, to apply it.

Naturally, before you attempt this, you really ought to read my sig. ;)

EDIT: It's now on the wiki.

http://wiki.simplemachines.org/smf/Patching

In the section marked "Obtaining the patch". :)
« Last Edit: October 10, 2011, 12:36:17 PM by K@ »

Offline Clara Listensprechen

  • Jr. Member
  • **
  • Posts: 256
  • Gender: Female
  • Impossible Person
    • clara.listensprechen on Facebook
    • @ClaraListenspre on Twitter
    • Clara's Cranny blog
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #152 on: October 10, 2011, 03:43:50 PM »
Ahem...

Clara, I had the same problem that you had.

I know not why, nor do I know how to fix it.

BUT (And I think this should go in the documentation, too. I'm about to attempt to do that.), there's an easy way around it, you'll be pleased to know.

Get the upgrade archive/package and upload it, STILL ARCHIVED, into your Packages directory, using your FTP client.

Then, go to Package manager, to apply it.

Naturally, before you attempt this, you really ought to read my sig. ;)

EDIT: It's now on the wiki.

http://wiki.simplemachines.org/smf/Patching

In the section marked "Obtaining the patch". :)
Thanks k@. Other responses to this difficulty amount to "I pity da foo who don't know which section of this large board to go to to find stuff when time is of the essence".  Just navigation of this board alone is a time consuming research project, let alone figuring that Wiki is yet another place to spend quality research wheelspinning time on.  Many thanks.

=========================

By golly, what I needed to know  is in this one single line:

Quote
In some cases, the upload to Packages may be corrupted, when you attempt this. In this case, you can upload the file (Still archived) to your Packages directory, using your FTP client. Then, go to Package Manager, to apply it.
Now how hard is it to just post THAT. Gee. And now anybody else coming to this thread FIRST (like I did) for that piece of information won't have to spend all friggin day looking through all the boards just to get rerouted to Wiki to spend the rest of the day over there. K@, lotsa smooches, you're a lifesaver!!

This deal with upgrading via the Package Manager has always been an issue, and it's always been the case in the past that manually unpacking an upgrade and then overwriting files (modifications be damned) the way it was done. Nobody should be surprised when the Package Manager does what it's been doing as usual...least of all support people.
« Last Edit: October 10, 2011, 04:03:01 PM by Clara Listensprechen »
I shall continue to be an impossible person so long as those who are now possible remain possible. {Michael Bakunin 1814-1876}

Offline IchBin™

  • SMF Friend
  • SMF Super Hero
  • *
  • Posts: 11,115
  • Gender: Male
  • I don't speak German.
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #153 on: October 10, 2011, 04:10:52 PM »
Clara,

Part of the problem is that the suggestion that fixed it for you is one of 20 suggestions that could have been said. And even then, I've seen many hosts still not work after such suggestions. Depending on server configuration many things could be the problem for this. I'm glad you found what worked for you, and it's always useful when someone types what fixed it for them so thank you.

-IchBin
IchBin™        TinyPortal
Coding Guidelines       

kat

  • Guest
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #154 on: October 10, 2011, 04:41:29 PM »
By golly, what I needed to know  is in this one single line:

Quote
In some cases, the upload to Packages may be corrupted, when you attempt this. In this case, you can upload the file (Still archived) to your Packages directory, using your FTP client. Then, go to Package Manager, to apply it.

That's part of what I just added, there. :)

Offline Ashley S

  • Sr. Member
  • ****
  • Posts: 985
  • Gender: Male
    • @AsHWM on Twitter
    • AdminMB
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #155 on: October 12, 2011, 01:00:06 PM »
Great release guys.
Keep it up.

Offline Jim_Di

  • Semi-Newbie
  • *
  • Posts: 12
    • Our forum
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #156 on: October 14, 2011, 06:04:20 AM »
in Display.php line 1380 and 1381
Code: [Select]
if ($context['browser']['is_firefox'])
header('Content-Disposition: ' . $disposition . '; filename*="UTF-8\'\'' . preg_replace('~&#(\d{3,8});~e', '$fixchar(\'$1\')', $utf8name) . '"');


strange «*» at the left side of «=» is a reason for FF 8 glitches - when u try download attachment name of file index.php insted of normal attach name.

we're change line 1381 to
Code: [Select]
header('Content-Disposition: ' . $disposition . '; filename="' . preg_replace('~&#(\d{3,8});~e', '$fixchar(\'$1\')', $utf8name) . '"');
and it's work normally
strange Russian programmer
jabber: jimdi@kgn.ru

Offline Angelina Belle

  • SMF Friend
  • SMF Hero
  • *
  • Posts: 7,586
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #157 on: October 18, 2011, 04:25:16 PM »
Hello Jim_Di,

Thanks for the bug report.
I think this is the issue tracked as http://dev.simplemachines.org/mantis/view.php?id=4825

If you find any more bugs, please post them to the bug reports board (http://www.simplemachines.org/community/index.php?board=137.0)
Never attribute to malice that which is adequately explained by stupidity. -- Hanlon's Razor

Offline Illori

  • Project Manager
  • SMF Legend
  • *
  • Posts: 51,133
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #158 on: October 22, 2011, 06:14:51 AM »
please start a thread in the proper support board, this thread is not for support.

Offline Alex' Manson

  • Full Member
  • ***
  • Posts: 506
  • Gender: Male
  • dead and gone!
    • Sisko Hosting - FREE|PAID Hosting
Re: SMF 2.0.1 and 1.1.15 critical security patches released
« Reply #159 on: November 05, 2011, 11:31:40 AM »
Thank you for the patch.