Mambo forums
Forum Home Register Forum Rules FAQ Search Today's Posts Mark Forums Read

Go Back   Mambo CMS Forum > Mambo Announcements > Mambo Security Announcements
 

Security issue identified and patched - please update now

This is a discussion on Security issue identified and patched - please update now within the Mambo Security Announcements forums for Mambo.

Reply
 
Thread Tools
Old 12-02-2008, 05:10 AM   #1
Elpie
Mambo Guru
Forum Admin
 
Elpie's Avatar
 
Join Date: Jul 2006
Location: New Zealand
Posts: 10,001
Security issue identified and patched - please update now

We have been alerted to a security issue with MOStlyCE version 2.3 that is included in the Mambo distro: http://secunia.com/advisories/28670/

We had already hardened security and were intending to release MOStlyCE version 2.4 with Mambo 4.6.4. However, in light of the seriousness of these reported vulnerabilities, and the release of a much-improved TinyMCE 11 days ago, we have instead chosen to use the newly released TinyMCE, version 3.0. The announcement is here: http://forum.mambo-foundation.org/sh...ad.php?p=54375

The vulnerabilities that were identified are pretty nasty so you are all urged to update your editor as soon as possible.

MOStlyCE 3.0 will be included in Mambo 4.6.4 and all previous versions of MOStlyCE should be replaced.

Installation instructions are included and this kb doc will give you more details:
http://mambo-support.org/en/entry/126/

Last edited by Elpie; 19-08-2008 at 11:01 AM. Reason: updated link to upgrade instructions
Elpie is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 07:58 AM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Mambo Foundation, Inc © 2000 - 2008 All rights reserved. Mambo is Free Software released under the GNU/GPL License.

Managed Servers by DedicatedNOW