[消息]phpBB2.0.12釋出=.=

網站架設,免費空間申請,架站技術交流區
Martinet
 

[消息]phpBB2.0.12釋出=.=

文章Martinet » 2005-02-22 11:18 am

原文: http://www.phpbb.com/phpBB/viewtopic.php?t=265423


phpBB Group are pleased to announce the release of phpBB 2.0.12 the "Horray for Furrywood" release. This release addresses a number of bugs and a couple of potential exploits. It also adds a new feature in the form of an ACP based version checker (maintainers of language packages please take note of the need for the additional localised string!).

Please note, the exploits of which we've been notified and which are addressed in 2.0.12 are in absolutely no way to blame for the loss of www.phpbb.com which we are still extremely confident was the fault of an outdated awstats and kernel.

However one of the potential exploits addressed in this release could be serious in certain situations and thus we urge all users, as always, to upgrade to this release as soon as possible. Mostly this release is concerned with eliminating disclosures of information which while useful in debug situations may allow third parties to gain information which could be used to do harm via unknown or unfixed exploits in this or other applications.

As with previous releases three different packages are available:
  • Full Package
    Contains entire phpBB2 source and English language package
  • Changed Files Only
    Contains only those files changed from previous versions of phpBB. Please note this archive contains changed files for each previous release
  • Patch Files
    Contains patch compatible patches from the previous versions of phpBB.


Select whichever package is most suitable for you.

Please ensure you read the INSTALL and README documents in docs/ before proceeding with installation or updates!.

Note to 2.0.3 users intending to use the patch file version

Users of 2.0.3 intending to use the patch version may (but not necessarily will) need to run fixfiles.sh (found in the contrib/ directory with the downloaded archive) before patching.

We recommend that all 2.0.3 users do a "dry run" patch first to see whether this you need to use this fix. To do this append --dry-run to the patch command, e.g. patch -cl -p1 --dry-run < phpBB-2.0.3_to_2.0.12.patch. This will prevent any permanent changes being made to your installation. If you experience numerous (literally dozens and dozens) of hunk failed messages this applies to you.

To correct this problem go to your phpBB root directory, copy the fixfiles.sh to this location, chmod u+x fixfiles.sh and type ./fixfiles.sh. This will strip windows style carriage returns present in the 2.0.3 source

What has changed in this release?

The changelog (contained within this release) is as follows:



    Added confirm table to admin_db_utilities.php

    Prevented full path display on critical messages

    Fixed full path disclosure in username handling caused by a PHP 4.3.10 bug - AnthraX101

    Added exclude list to unsetting globals (if register_globals is on) - SpoofedExistence

    Fixed arbitrary file disclosure vulnerability in avatar handling functions - AnthraX101

    Fixed arbitrary file unlink vulnerability in avatar handling functions -AnthraX101

    Removed version number from powered by line

    Merged database update files to update_to_latest.php file

    Fixed path disclosure bug in search.php caused by a PHP 4.3.10 bug (related to AnthraX101's discovery)

    Fixed path disclosure bug in viewtopic.php caused by a PHP 4.3.10 bug - matrix_killer



原文: http://www.phpbb.com/phpBB/viewtopic.php?t=265444

Classification: 48 phpBB Installation & Upgrade Tools

MOD Name: phpBB 2.0.11 to phpBB 2.0.12 Code Changes
Author: Acyd Burn
MOD Description: Code Changes from phpBB 2.0.11 to 2.0.12 in three formats (text/mod, html, bbcode prepared for posting the changes on phpBB forums).


MOD Version: 1.0.0
Installation Level: Intermediate
Installation Time: ~ 10 Minutes

Download File: phpbb_2011_to_2012.zip
File Size: 22689 Bytes

Security Score: 0





K
企鵝管理員
 
文章: 1118
註冊時間: 2003-05-19 11:00 am
來自: 囧星
性別: 男生

文章K » 2005-02-22 11:57 am

MM有裝嗎?


........圖檔
圖檔


ETERNAL
 
文章: 2937
註冊時間: 2003-12-03 11:08 pm
性別: 男生

文章ETERNAL » 2005-02-22 2:26 pm

等晚上回家後在升級吧
對了,我寫的子版面已經寫好安裝說明,MM有空拿去裝起來測試看看吧


水色論壇 http://www.et99.net
簡恩峻分享

Martinet
 

文章Martinet » 2005-02-22 2:39 pm

ETERNAL 寫:等晚上回家後在升級吧
對了,我寫的子版面已經寫好安裝說明,MM有空拿去裝起來測試看看吧


喔喔@@
想放在竹貓上了嘛?:P
好啊好啊

K 寫:MM有裝嗎?


還沒|||
還沒空裝XD

忙著感冒orz




K
企鵝管理員
 
文章: 1118
註冊時間: 2003-05-19 11:00 am
來自: 囧星
性別: 男生

文章K » 2005-02-22 3:03 pm

PLUS~可以用嗎@@?


........圖檔
圖檔


ETERNAL
 
文章: 2937
註冊時間: 2003-12-03 11:08 pm
性別: 男生

文章ETERNAL » 2005-02-23 12:04 am

水色升級完畢

你是說子版面可以用在PLUS嗎?


水色論壇 http://www.et99.net
簡恩峻分享


K
企鵝管理員
 
文章: 1118
註冊時間: 2003-05-19 11:00 am
來自: 囧星
性別: 男生

文章K » 2005-02-23 12:26 am

我是說2.0.12@@||


........圖檔
圖檔

Martinet
 

文章Martinet » 2005-02-23 10:10 am

應該可以吧
不過要注意一下 phpBB plus 是 based on which version

然後從該 version 升級

而非直接用2.0.12升級^^||




K
企鵝管理員
 
文章: 1118
註冊時間: 2003-05-19 11:00 am
來自: 囧星
性別: 男生

文章K » 2005-02-23 11:34 am

Orz...難怪我第一個檔案要找的東西就找不到了..

等PLUS 1.52版的出來吧Orz..


........圖檔
圖檔


回到 架站討論

誰在線上

正在瀏覽這個版面的使用者:沒有註冊會員 和 7 位訪客