News:

Want to get involved in developing SMF, then why not lend a hand on our github!

Main Menu

SMF 2.0.2 and 1.1.16 critical security patches released

Started by Norv, December 22, 2011, 11:43:01 PM

Previous topic - Next topic

cerbopoli

Thanks CoreISP.  I will ask on the support boards as that is exactly what I have done and it is not working. 

live627


KVL

Updates is ​​successfully. :) Thank you very much for your work! :) Merry Christmas and Happy New Year! :)

MarkRH

Weird. My locally installed forum on my PC sees that the update is available but on my production one, the Administration center does not say an update is available. It also does not show the latest message in the "Live from Simple Machines forum" section about SMF 2.0.2 being available, just the SMF 2.0.1 and earlier messages.  Hmmm..

Well, I uploaded the 2.0.2 patch file manually and installed it via the Package Manager.  I still wonder why my local installation sees the 2.0.2 message in the Admin area and the installation at my webhost does not.  Bizarre.  It's like my server and SMF's server aren't on speaking terms for some reason.

I figured it out. The Fetch Simple Machines Files task failed this morning. I saw it in my error log. I manually ran the task and now I see the updated postings about 2.0.2.  I may need to adjust the time of day it does these checks as it seems to correspond with a lot of other server maintenance tasks at my host. At least I know what happened now. :)
Mark H.

Jntg4

Thanks for Simply Machines Forum 2.0.2, Simple Machines Forum 1.1.16, and Simple Machines Forum 1.0.22!
Free Domain Name: http://www.co.cc/?id=167358

Sapozhnik

Quote from: phantomm on December 23, 2011, 02:04:15 PM
Update for SMF 2.0.1 contains fix for problems with downloading attachments by FF?

and this is fixed in this patch?

This problem was fix in FF 9.0.1
Update it ;)

Linda.V

Quote from: MarkoKg on December 23, 2011, 06:04:50 AM
I would like to manually manage the update, as this is just small update when i update 2.0.1 to 2.0.2 i guess? I have planty of mods installed and many code changes so i want to be sure that everything will be okay, and i want to manually install this patch, if it's possible?

Quote from: Illori on December 23, 2011, 06:30:02 AM
for those that want a parse of the 2.0.1 -> 2.0.2 package http://custom.simplemachines.org/upgrades/index.php?action=upgrade;file=smf_patch_2.0.2.tar.gz;smf_version=2.0.1

Idem on my forum where I installed some mods manual. So thanks for the parse of the 2.0.1 -> 2.0.2

Antes


oziboy

Yes, thanks to the Team for the update. I installed 2.02 through Package Manager - so smooth and quick.



Enc0der

#70
Thank you,

Although I'm very disappointed that this update didn't fix the known "attachments bug" with firefox 8 - since I consider it a major bug, end-user wise.
http://dev.simplemachines.org/mantis/view.php?id=4825
There's already a patch for it (but weird, because there is no file named "Attachment.php" in the /Sources directory.. It should be Display.php), so why it is not included in the release?

spiros

Strangely enough this forum appears still unpatched:

SMF 2.0.1 | SMF © 2011, Simple Machines

Illori

we have to wait for the site team to have the time to do the upgrade, they do not use the patches like the rest of us do.

gisfreak

Me fail English? That's unpossible.

kat

Quote from: Enc0der on December 24, 2011, 09:10:25 AMwhy it is not included in the release?

Pure guess: The bug is with Firefox, not SMF. So, we're going to have to figure a fix that won't screw everything for users of proper browsers.

Oddly enough, Firefox v9 works as it should. :)

Enc0der

Quote from: K@ on December 24, 2011, 11:45:55 AM
Pure guess: The bug is with Firefox, not SMF.
Not true :)

Anyway, it is indeed "fixed" in Firefox 9.


Illori

you can find the changelog on the downloads page and in the archives.

SleePy

Quote from: spiros on December 24, 2011, 09:11:41 AM
Strangely enough this forum appears still unpatched:

SMF 2.0.1 | SMF © 2011, Simple Machines
I think you misread the numbers ;D


Quote from: Enc0der on December 24, 2011, 09:10:25 AM
Although I'm very disappointed that this update didn't fix the known "attachments bug" with firefox 8 - since I consider it a major bug, end-user wise.
http://dev.simplemachines.org/mantis/view.php?id=4825
There's already a patch for it (but weird, because there is no file named "Attachment.php" in the /Sources directory.. It should be Display.php), so why it is not included in the release?

The Attachment.php is for SMF 2.1, so that is why it is the wrong file.

Norv said he forgot about including that fix when making the release.  Getting this release was critical and he was short on time.  Because of the Holiday times, there wasn't enough time to add in the changes and test them after we realized that.
I am glad to hear reports that FF 9 fixed it on their end.  I read somewhere in a Mozilla article/posting (i think a bug post) that their data shows most users are either on 3.6 or following the 6 week updates.  There was a small chunk of them still resisting on FF 7 though.  So this is good news at least :)
Jeremy D ~ Site Team / SMF Developer ~ GitHub Profile ~ Join us on IRC @ Libera.chat/#smf ~ Support the SMF Support team!

David111567

Administration Center tells me there's NO update available...so I go download the upgrade to do it manually.  5th time I've downloaded it and I get the message:

"Package upload failed due to the following error:
"Although the package was downloaded to the server it appears to be empty. Please check the Packages directory, and the "temp" sub-directory are both writable. If you continue to experience this problem you should try extracting the package on your PC and uploading the extracted files into a subdirectory in your Packages directory and try again. For example, if the package was called shout.tar.gz you should:
1) Download the package to your local PC and extract it into files.
2) Using an FTP client create a new directory in your "Packages" folder, in this example you may call it "shout".
3) Upload all the files from the extracted package to this directory.
4) Go back to the package manager browse page and the package will be automatically found by SMF.""


When ADMIN doesn't see an update...and when the zip files from your own site are EMPTY...how the heck can I do an upgrade.  Also...this is a heck of a thing to do on Christmas Eve on 6 production sites!

In 5 years I have never had this much problems with an SMF upgrade.  Ever.

Merry Christmas.

Advertisement: