Christophe Posted November 26, 2015 Posted November 26, 2015 We need to rebuild our server due to old php and mysql so the upgrade from 4.1.3.2 is not going to go through How critical is the upgrade from 4.1.3.2 to 4.1.4.1 because I have to wait for a good week now with the holidays then there is a lot of testing to be done If there is a hole somewhere I need to plug it but I can t do it for a week...can I just replace the old files that are in the patch on the server and wait? would that at least patch the hole even if the upgrade is not run?
MADMAN32395 Posted November 26, 2015 Posted November 26, 2015 3 minutes ago, Christophe said: We need to rebuild our server due to old php and mysql so the upgrade from 4.1.3.2 is not going to go through How critical is the upgrade from 4.1.3.2 to 4.1.4.1 because I have to wait for a good week now with the holidays then there is a lot of testing to be done If there is a hole somewhere I need to plug it but I can t do it for a week...can I just replace the old files that are in the patch on the server and wait? would that at least patch the hole even if the upgrade is not run? Additional Information Two security resolutions are included in this release: Special circumstances made it possible to reveal the AdminCP session ID. The image proxy feature that could lead to out of memory errors when processing certain images. An XSS issue in Gallery is present in certain circumstances. We would like to thank LinusMediaGroup for reporting the AdminCP session ID issue to us responsibly. We would like to thank Stephan Brunner (Twitter: @boomer41_net) and Tobias Sachs (Twitter: @Knightyyyy1) for reporting and working with us on the image proxy issue. We would like to thank batpool52! for reporting the Gallery XSS issue to us responsibly. Basically. I would recommend upgrading.
Christophe Posted November 26, 2015 Author Posted November 26, 2015 ok cool thanks. Yeah I m upgrading but 9 women can t make a baby in a month...I got to wait for the hosting company to rebuild a new server for us Not using Gallery is behind htaccess so I guess I can live with this for a week Thanks again
Recommended Posts
Archived
This topic is now archived and is closed to further replies.