You are here: Gregarius - Devlog » 2005 » 11 » 01

Archive for November 1st, 2005

Security Update

A security hole, which allows for arbitrary code execution, has been recently discovered in the Snoopy web client library, which is bundled with Gregarius.

Only Gregarius installations which are publicly accessible on the Internet, and whose administration area is not password-protected are affected, but to avoid unnecessary risk Gregarius 0.5.2 has been re-released with a fix for this security hole. You are strongly encouraged to upgrade your installation.

You should either:

  • Download the updated release from sourceforge.net: make sure you download either of rss-0.5.2a.tar.gz or rss-0.5.2a.zip, or:

  • Replace the rss/extlib/Snoopy.inc.php file with the fixed version, or:

  • Upgrade your installation using a nightly build.

We apologize for the inconvenience :)

Posted by Marco at Nov 1st 2005, 8:01 pm | Filed under: releases, bugs, gregarius | No Comments
Sponsored links

Credit Cards | Free Advertising | Mobile Phone | Teen Chat | Free Advertising