Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <2100079136.186211280779059938.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Mon, 2 Aug 2010 15:57:39 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley <coley@...re.org>
Subject: Re: CVE request: cmsmadesimple < 1.8.1

Please use CVE-2010-2797

Thanks.

-- 
    JB


----- "Hanno Böck" <hanno@...eck.de> wrote:

> http://www.cmsmadesimple.org/2010/07/3/announcing-cms-made-simple-1-8-1-
> mankara/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+cmsmadesimple%2Fblog+%28CMS+Made+Simple%29
> 
>  NOTE: This release fixes an important security vulnerability,
> we recommend that ALL users upgrade as soon as possible.
> 
> The local inclusion vulnerability fixed is old and affects many
> previous versions of CMSMS. Therefore it is important for ALL
> installations to be upgraded as soon as possible.
> 
> This release also fixes all of the issues encountered with the
> CMSMS 1.8 release due to the overhaul of the translation function.
> Your performance in the admin section should be back to normal
> following this upgrade.
> 
> Below is a complete list of the remaining issues that have been
> addressed in this release, enjoy.
> 
> Version 1.8.1 - Mankara
> 
> 
> Security:
> 
>     Fixed local inclusion security flaw
> -- 
> Hanno Böck		Blog:		http://www.hboeck.de/
> GPG: 3DBD3B20		Jabber/Mail:	hanno@...eck.de
> 
> http://schokokeks.org - professional webhosting

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.