Jump to content

I have to wait for the upgrade, how critical is 4.1.4.1?


Christophe

Recommended Posts

We need to rebuild our server due to old php and mysql so the upgrade from 4.1.3.2 is not going to go through

How critical is the upgrade from 4.1.3.2 to 4.1.4.1 because I have to wait for a good week now with the holidays then there is a lot of testing to be done

If there is a hole somewhere I need to plug it but I can t do it for a week...can I just replace the old files that are in the patch on the server and wait?

would that at least patch the hole even if the upgrade is not run?

 

Link to comment
Share on other sites

3 minutes ago, Christophe said:

We need to rebuild our server due to old php and mysql so the upgrade from 4.1.3.2 is not going to go through

How critical is the upgrade from 4.1.3.2 to 4.1.4.1 because I have to wait for a good week now with the holidays then there is a lot of testing to be done

If there is a hole somewhere I need to plug it but I can t do it for a week...can I just replace the old files that are in the patch on the server and wait?

would that at least patch the hole even if the upgrade is not run?

 

 

Additional Information

Two security resolutions are included in this release:

  • Special circumstances made it possible to reveal the AdminCP session ID.
  • The image proxy feature that could lead to out of memory errors when processing certain images.
  • An XSS issue in Gallery is present in certain circumstances.

 

We would like to thank LinusMediaGroup for reporting the AdminCP session ID issue to us responsibly.

We would like to thank Stephan Brunner (Twitter: @boomer41_net) and Tobias Sachs (Twitter: @Knightyyyy1) for reporting and working with us on the image proxy issue.

We would like to thank batpool52! for reporting the Gallery XSS issue to us responsibly.

 

Basically. I would recommend upgrading.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...