GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   WORDPRESS USERS - Security Update! (https://gfy.com/showthread.php?t=696197)

Jace 01-15-2007 04:54 PM

WORDPRESS USERS - Security Update!
 
http://wordpress.org/download/

http://wordpress.org/development/2007/01/wordpress-207/

Recently a bug in certain versions of PHP came to our attention that could cause a security vulnerability in your blog. We?re able to work around it fairly easily, so we?ve decided to release 2.0.7 to fix the PHP security problem and the Feedburner issue that was in 2.0.6. It is recommended that everyone running WordPress 2.0.6 or lower upgrade to this new version.

Because this is a much smaller update than previous versions, you do not have to update all of WordPress? files if you?re upgrading from version 2.0.6. Here is the list of files that have changed since 2.0.6:

* wp-admin/inline-uploading.php
* wp-admin/post.php
* wp-includes/classes.php
* wp-includes/functions.php
* wp-settings.php
* wp-includes/version.php

We know it sucks to have a release only 10 days after our last one, but we think it?s important enough for your blog to be secure to do it, and hopefully only having to change a few files will make the upgrade easier than normal.

Here are the changes that have been made since 2.0.6:

* Security fix for wp_unregister_GLOBALS() to work around the zend_hash_del_key_or_index bug in PHP 4 versions less than 4.4.3 and PHP 5 versions less than 5.1.4 with register_globals set to ?On.?
* Feeds now properly serve 304 Not Modified headers instead of mismatched 200/304 headers (a.k.a. the FeedBurner bug).
* Backport of another 304 Not Modified fix from WordPress 2.1
* Deleting WordPress Pages no longer gives an ?Are You Sure?? prompt.
* After deleting a WordPress Page, you are now properly redirected to the Edit Pages screen.
* Sending an image at original size in Internet Explorer no longer adds an incorrect ?height? attribute.

And just as a reminder, the next major version of WordPress (2.1) is due out by the end of the month, but the 2.0 branch of WordPress will continue to be maintained for several years.

Dirty F 01-15-2007 04:55 PM

Sucks if you have 500 blogs.

woj 01-15-2007 04:57 PM

lame, only a week has passed since the last update... :(

Jace 01-15-2007 04:58 PM

Quote:

Originally Posted by Dirty Franck (Post 11735944)
Sucks if you have 500 blogs.

heh, yeah, no shit

fantastico is nice for that though, but still annoying as shit

Jace 01-15-2007 04:59 PM

Quote:

Originally Posted by woj (Post 11735954)
lame, only a week has passed since the last update... :(

yeah, it seemed like the last update was just a few days ago

luckily this one is just a drop and replace

Sarah_Jayne 01-15-2007 04:59 PM

Well, I guess I know what I am doing tomorrow.

ucv.karl 01-15-2007 05:05 PM

Quote:

Originally Posted by woj (Post 11735954)
lame, only a week has passed since the last update... :(

And this gem.

"And just as a reminder, the next major version of WordPress (2.1) is due out by the end of the month, but the 2.0 branch of WordPress will continue to be maintained for several years."

Scroto 01-15-2007 05:05 PM

just finished updating...again :disgust

Jace 01-15-2007 05:11 PM

Quote:

Originally Posted by ucv.karl (Post 11735991)
And this gem.

"And just as a reminder, the next major version of WordPress (2.1) is due out by the end of the month, but the 2.0 branch of WordPress will continue to be maintained for several years."

OMFG

haha, what a bunch of tools

RawAlex 01-15-2007 05:14 PM

These guys need to learn how to do live updates. This constant updating and patching bullshit is turning their product into work.

StarkReality 01-15-2007 05:20 PM

Argh...paching is nice, but if it continues this way, we'll get daily updates and I'll hire a wordpress updater...

JD 01-15-2007 05:24 PM

i'll just wait for end of the month update

Babaganoosh 01-16-2007 12:06 AM

Quote:

Originally Posted by RawAlex (Post 11736051)
These guys need to learn how to do live updates. This constant updating and patching bullshit is turning their product into work.

Yeah, for what you paid for it I would complain too.

martinsc 01-16-2007 12:09 AM

thanks for the heads up

tenderobject 01-18-2007 04:50 AM

hey jace, this only affects wordpress 2.0.6 version or all the wordpress version need to be upgraded?

cachondo 01-18-2007 04:54 AM

My blog site has hacked, shit!

Bliggo 01-18-2007 04:59 AM

Quote:

Originally Posted by tenderobject (Post 11748473)
hey jace, this only affects wordpress 2.0.6 version or all the wordpress version need to be upgraded?

This applies to all versions as .0.5 fixed stuff from 0.4 which fixed stuff from 0.3 etc etc.

ps I used version numbers for example only.


All times are GMT -7. The time now is 03:20 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123