Pages (4): 1 2 3 4   
Administrator
Administrator
acrylian   11-11-2011, 11:05
#1

More info on:
http://www.zenphoto.org/news/zenphoto-1.4.1.6

Member
Member
hucste   11-11-2011, 12:15
#2

Thanks to act as !
It's very good thing...

Member
Member
Ipstenu   11-11-2011, 16:31
#3

Is there any difference to the manual changes I made yesterday for 1.4.1.5? (I use SVN to manage my install and I'm loath to download and change if I already took care of it by manually removing it).

Administrator
Administrator
acrylian   11-11-2011, 17:14
#4

No, the 1.4.1.6 release (as noted on the post) just incorporates the changes mentioned on the 2nd security post. Otherwise it is just 1.4.1.5. Btw, that is mentioned in the release post's first sentence..;-)

Again, note that the svn trunk is NOT 1.4.1.6 but already 1.4.2 beta (the dev svn stream as well) as the 1.4.1.x line was actually considered complete. This has been announced a week or so ago.

Member
Member
Michel Gagnon   12-11-2011, 03:25
#5

A slightly different question: I have downloaded and installed the 1.4.3 DEV (8385) version and done the corrections you suggested in the "Security alert - Part 2 update 2". Am I OK?

P.S. One site was hacked, the other was not, but I cleaned and updated both anyways.

Administrator
Administrator
acrylian   12-11-2011, 10:29
#6

Yes, as far as we know. But I recommend to use the TRUNK svn as that wil become the next version 1.4.2. That is beta and will not get new features until the scheduled release (see roadmap on the bugtracker. Using this will help us find bugs we missed.

The DEV svn is for 1.4.3 somewhere in the future. Currently both are still the same but soon this one might get experimental. So we can't recommend to use this on a live site currently.

Member
Member
mironb   13-11-2011, 13:13
#7

Hi
Mi site was also hacked. I think no is clear but I didn't deleted jpg files with photos. How can I check are they not infected ?

Administrator
Administrator
acrylian   14-11-2011, 10:41
#8

I would say try a virus scan for the start.

Junior Member
Junior Member
oscardog   17-11-2011, 22:50
#9

After being affected by this loophole and clearing out the old install when I come to upload (cPanel) the install package my hosts system is rejecting the 1.4.1.6.zip saying it contains a virus (scanner is probably ClamAV).

I can not get any details as to which file it objects to.

Has this been an issue for anyone else?

Member
Member
BernardJL   18-11-2011, 00:12
#10

Maybe we are missing something here. Without the "ajax file manager" we cannot use the "Files" tab under "Upload".

Which seems to mean the only way to add photos is via the web page upload.

Is there some other way to get Zenphoto to process files we already have copied to the server? That has always been our preferred method to load pictures.

Any help is appreciated.

Pages (4): 1 2 3 4   
  
Powered By MyBB, © 2002-2026 MyBB Group.
Made with by Curves UI.