NYCPHP Meetup

NYPHP.org

[mambo] Mambo 4.5.2.2 is out! [SECURITY PATCH]

Mitch Pirtle mitch.pirtle at gmail.com
Thu Jun 2 08:31:35 EDT 2005


Nope, as they didn't include the domit xml parsing library. Basically
4.5.1 and up need to be upgraded with 4.5.2.2.

-- Mitch

On 6/2/05, Chris Hendry <chris.hendry at nyphp.org> wrote:
> This does not include earlier versions?
> 
> | -----Original Message-----
> | From: mambo-bounces at lists.nyphp.org
> | [mailto:mambo-bounces at lists.nyphp.org] On Behalf Of Mitch Pirtle
> | Sent: Thursday, June 02, 2005 12:15 AM
> | To: NYPHP SIG: Mambo
> | Subject: [mambo] Mambo 4.5.2.2 is out! [ECURITY PATCH]
> |
> | Hi gang,
> |
> | Apologies for the cross post.
> |
> | There was a security issue found in the included domit-xml
> | xml parsing library in the current version of Mambo, which we
> | have fixed with this release (4.5.2.2). The vulnerability
> | includes information disclosure, including the contents of
> | your configuration.php - so this is an immediate, critical upgrade.
> |
> | You can get the full version or patch at MamboForge:
> |
> |     http://mamboforge.net/frs/?group_id=5
> |
> | --
> | Mitch Pirtle
> | Mambo Core Developer
> | _______________________________________________
> | New to Mambo? Get a great start here:
> | http://forum.mamboserver.com/showthread.php?tB100
> |
> | New York PHP SIG: Mambo Mailing List
> | AMP Technology
> | Supporting Apache, MySQL, PHP &amp; Mambo!
> | http://lists.nyphp.org/mailman/listinfo/mambo
> | http://www.nyphp.org
> 
> _______________________________________________
> New to Mambo? Get a great start here:
> http://forum.mamboserver.com/showthread.php?t=42100
> 
> New York PHP SIG: Mambo Mailing List
> AMP Technology
> Supporting Apache, MySQL, PHP &amp; Mambo!
> http://lists.nyphp.org/mailman/listinfo/mambo
> http://www.nyphp.org
>



More information about the Joomla mailing list