Nukemods Forum  
» Log in
User Name:

Password:

Not a member yet?
Register Now!
» Online Users: 88
6 members and 82 guests
breakinguptomak, cycwcwlinlt2gti, denzk9tistw6iwp, horbd4aseracidn, robaaerteqjc6xs, ssefqarchmar2dx
Most users ever online was 611, 03-21-2008 at 11:10 PM.
» .::.
tattoo fonts
http://www.checkoutmyink.com/category/tattoo-fonts-tattoo

Go Back   Nukemods Forum > Nukemods > News

Reply
 
LinkBack Thread Tools Display Modes
Critical Security Release Announcement From PHPBB Group
Old
  (#1 (permalink))
Administrator
 
Status: Offline
Posts: 125
Join Date: Feb 2002
Location: USA
Critical Security Release Announcement From PHPBB Group - 03-18-2010, 08:30 PM

From the PHPBB Group:

We are sorry to announce the immediate release of phpBB 3.0.7-PL1 to address a security issue which was introduced in 3.0.7, unfortunately the issue wasn't noticed during testing and has only surfaced a week after the release of 3.0.7.

We promised working feeds for phpBB 3.0.7. Sadly, we were not able to deliver on that promise - a critical bug in the permission handling for feeds slipped past. To all people who already have updated to 3.0.7, it is of critical importance to update to 3.0.7-PL1. Otherwise, it is possible for users to bypass permission settings under the following circumstances:

- Feeds are enabled
- Any of the posts or topics feeds are enabled
- The unauthorised user - or one of the groups they are a member of - has forum permissions set on a private forum
- If you have excluded a forum from the list of forums that provide feeds, it is unaffected

The fix for the issue is a single line change inside of feed.php, line 525 has changed from:

$forum_ids = array_keys($auth->acl_getf('f_read'));

to:

$forum_ids = array_keys($auth->acl_getf('f_read', true));

More...
   
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
PHPBB Critical Error- Please Help dfm123 Nuke 6.5 to 6.9 - Modules 2 05-18-2003 03:51 PM
phpBB : Critical Error Evil Open topics 4 04-26-2003 09:19 PM
RootGap Security Group cy4lock Showoff 0 04-03-2003 06:47 AM
phpBB : Critical Error & Warning milenko Purged Topics 8 02-18-2003 03:43 PM
phpBB : Critical Error macro Purged Topics 0 02-03-2003 10:57 PM




vBulletin Skin developed by: vBStyles.com


LinkBacks Enabled by vBSEO 3.3.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31