phpBB 3.2.4 Release - Please Update

Qui trovate raccolte le news provenienti da altri siti
Rispondi
Avatar utente
master_of_mouse
Amministratore
Amministratore
Messaggi: 9913
behance Kuchnie Warszawa
Iscritto il: 23 apr 2003 02:00
Scheda madre: Asus M4A89GTD Pro/USB3
CPU: AMD Penom II X4 BE 965
Ram: 2x 8GB 1600MHz 9-9-9-24
Scheda video: AMD Radeon RX 650 4Gb
HD: 1x Samsung 256GB 850 Pro - 2x WD 1TB WD1002FAEX - 1x WD 3TB WD30EFRX
Alimentatore: Cooler Master Silent Pro Gold 600W
Raffreddamento: CPU Thermalright Macho HR-02 - VGA Artic Cooling Accelero S1 Plus
Sistema operativo: Windows 10 Pro
Monitor: 2x Samsung P2450

phpBB 3.2.4 Release - Please Update

Messaggio da master_of_mouse »

Greetings everyone,

We are pleased to announce the release of phpBB 3.2.4 "Bertie's ‘stache". This version is a maintenance and security release of the 3.2.x branch which fixes one security issue and various issues reported in previous versions.

The security issue was discovered with a new exploitation technique called Phar deserialization. An attacker with control over a founder admin account could escalate to remote code execution by abusing PHP’s default unserialization of metadata in Phar files. More information about this technique can be found here.
In order to fix this issue we’ve removed the ability to define absolute paths in the Admin Control Panel. This resulted in the removal of setting the ImageMagick path, so make sure to have the GD image library available instead. A new event to generate thumbnails was added as replacement, so you’re able to write an extension that uses a different image library to generate thumbnails. We would like to thank Simon Scannell and Robin Peraglie of RIPS Technologies for their report and responsible disclosure. The issue has been assigned CVE-2018-19274.

The fixed issues include, among others, compatibility issues with PHP 7.2 and issues with removing users from the newly registered user group more than once.
Among the notable changes are the addition of the list-unsubscribe header to emails sent by phpBB and the ability to reset your password without entering the username.

The full list of changes is available in the changelog file within the docs folder contained in the release package. You can find the key highlights of this release on the wiki at https://wiki.phpbb.com/Release_Highlights/3.2.4 and a list of all issues fixed on our tracker at https://tracker.phpbb.com/issues/?filter=14790

The packages can be downloaded from our downloads page.

We recommend following these update instructions for updating your instance of phpBB.

The development team thanks everyone who contributed code to this release: Jakub Senko, MikelAlejoBR, kasimi, Zoddo, v12mike, hubaishan, 3D-I, Matt Friedman, Kailey Truscott, Alec, Alex Miles, Andrii Afanasiev, Anssi Johansson, DSR!, Daniel, Dark❶, David Colón, Ioannis Batas, Jim Mossing Holsteyn, Serge Skripchuk, Toxyy, rxu

If you have any questions or comments, we'll be happy to address them in the discussion topic.

- The phpBB Team

Source: http://www.phpbb.com/community/viewtopi ... &t=2492206
Rispondi