opensource Content Management
Home > Alle News > Serendipity 1.0.4 released

Serendipity 1.0.4 released

Dec 1st, 2006 | By | Category: Alle News
Bewertung:
1 Stern2 Sterne3 Sterne4 Sterne5 Sterne (No Ratings Yet)

This new Serendipity release addresses a local file inclusion security
issue discovered yesterday. It was possible to give a special parameter
to a serendipity file to include a file on your own web-tree (or other
files the webserver has read access to). If used on clear-text files,
this could be used to disclose information like the apache logfiles on
your website.


This error can only happen in a scenario with two prerequisites: Register_Globals needs to be turned on in your PHP configuration AND your webserver must ignore the default Serendipity .htaccess file. This .htaccess file usually prevents to directly call Serendipity's include files via HTTP. Thus we feel that only a very low percentage of installations should be affected by this bug.

However, Serendipity 1.0.4 is a recommended upgrade for everyone taking security responsibly, like we do. We are thankful to the community for inspecting Serendipity, searching for bugs and security issues and reporting them to us. In this case, many thanks to Majestic from the forums for notifying us. …(via Serendipity ){moscomment}

Bewertung:
1 Stern2 Sterne3 Sterne4 Sterne5 Sterne (No Ratings Yet)

Aufrufe:
Gelesen: 362 · heute: 0 · zuletzt: Samstag, 23. April 2011 - 01:30
Info:
Serendipity 1.0.4 released ist Beitrag Nr. 245
Autor:
opencm.de am 1. December 2006 um 11:16
Category:
Alle News
Tags:
Trackback:
Trackback URI

Leave Comment