Support Forum Project Downloads FAQ Documentation About Demo Tutorials
May 12, 2008, 12:39:54 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Coppermine Live-Demo 1.4
For those who want to preview Coppermine before actually installing it on a real production server we have created a Live-Demo. It is just a package that provides a local webserver with a pre-configured Coppermine install rolled into one package to preview the "real" Coppermine Photo Gallery on your Windows box. The webserver is being started by only executing one single file, so you don't have to go through the troubles of setting up a webserver environment on your local PC just for evaluation purposes. The sole purpose of the live-demo is to give you an impression how the admin backend of Coppermine looks and feels. It is only meant to be used for evaluation purposes. You mustn't run it as a production system, because it has deliberately been configured in an unsecure manner to provide a newbie-proof experience in the first place.
[more]
   Home   Help Search Login Register  
Pages: [1]   Go Down
  Send this topic  |  Print  
Author Topic: cpg1.4.18 Security release - upgrade absolutely mandatory!  (Read 15017 times)
0 Members and 1 Guest are viewing this topic.
Joachim Müller Topic starter
Administrator
Coppermine addict
*****

Karma: 104
Gender: Male
Posts: 38119


aka "GauGau"


WWW
« on: April 14, 2008, 09:16:15 AM »

The development team is releasing a security update for Coppermine in order to counter a recently discovered sql injection vulnerability. It is important that all users who run version cpg1.4.17 or older update to this latest version as soon as possible.

This is the only issue addressed in this release.

How to update:
If you are currently running 1.4.17 then you may patch your gallery by replacing your copy of bridge/coppermine.inc.php with the fixed version available here. This is the only issue addressed in this release.
Users running versions prior to 1.4.17 should update immediately by downloading the latest version from the download page page and follow the upgrade steps in the documentation.

Support:
If you have problems with this update, please use the Update support board. Do not post your issues to this announcement thread - they will be deleted without notice.

Why was cpg1.4.18 released only few days after the release of cpg1.4.17?
The 1.4.17 patch indeed does not fix the problem - it fixes a different problem, one which this latest attack does not actually exploit. This new release will address the current issue.
That has been corrected in this version 1.4.18.
Version 1.4.18 contains sets of corrections already present in version 1.4.17.

Note: for galleries that have already been infected, it is not enough to upgrade - you'll have to sanitize your website as well. Upgrading will only close the vulnerability, but not the payload of the hack. Please review the thread that discusses the hack for suggestions how to sanitize - do not clutter the announcement thread for the release of cpg1.4.18 with questions/comments on the hack.

Big thanks go to Nibbler who came up with the fix for the vulnerability.

Thanks,
The Coppermine Team
« Last Edit: April 14, 2008, 01:06:55 PM by Joachim Müller » Logged

Don't contact me over PM or email unless I asked you to. Instead: post on the proper board. All unrequested messages will be ignored and your negative karma will no doubt increase!
Like my avatar? Create a free custom avatar just like mine.
maxslug
Coppermine newbie


Karma: 0
Posts: 6


« Reply #1 on: April 19, 2008, 02:06:17 AM »

Please update or delete the 1.4.17 announcement thread to say that it superseded by this update.  otherwise you google the hack, find the 1.4.17 page, update and have the same problems.  thanks!
-m
Logged
Abbas Ali
Dev Team member
Coppermine addict
****

Karma: 30
Gender: Male
Posts: 1378


Spread the PHP Web


WWW
« Reply #2 on: April 19, 2008, 11:03:28 AM »

cpg1.4.17 announcement thread updated. Thanks for notifying.
Logged

--- Love is blind, wish it was mute too ---
Visit me @ www.abbasali.net
ammo
Coppermine newbie


Karma: 0
Posts: 4


« Reply #3 on: April 22, 2008, 01:45:36 AM »

The development team is releasing a security update for Coppermine in order to counter a recently discovered sql injection vulnerability. It is important that all users who run version cpg1.4.17 or older update to this latest version as soon as possible.


Note: for galleries that have already been infected, it is not enough to upgrade - you'll have to sanitize your website as well. Upgrading will only close the vulnerability, but not the payload of the hack. Please review the thread that discusses the hack for suggestions how to sanitize - do not clutter the announcement thread for the release of cpg1.4.18 with questions/comments on the hack.

Big thanks go to Nibbler who came up with the fix for the vulnerability.

Thanks,
The Coppermine Team

Where can I find the thread on the hack suggestions?
Logged
Joachim Müller Topic starter
Administrator
Coppermine addict
*****

Karma: 104
Gender: Male
Posts: 38119


aka "GauGau"


WWW
« Reply #4 on: April 22, 2008, 08:07:41 AM »

Hack thread: http://forum.coppermine-gallery.net/index.php/topic,51671.0.html
Sanitization thread: http://forum.coppermine-gallery.net/index.php/topic,51927.0.html
Logged

Don't contact me over PM or email unless I asked you to. Instead: post on the proper board. All unrequested messages will be ignored and your negative karma will no doubt increase!
Like my avatar? Create a free custom avatar just like mine.
Medievaldragon
Coppermine newbie


Karma: -1
Posts: 2


« Reply #5 on: April 24, 2008, 09:14:41 PM »

Alright, I'm a first timer upgrading.  I will follow the instructions. thanks.
« Last Edit: April 24, 2008, 09:25:51 PM by Medievaldragon » Logged
Pascal YAP
Dev Team member
Coppermine addict
****

Karma: 24
Gender: Male
Posts: 3096


He's not me, it's my Avatar (PYAP)


WWW
« Reply #6 on: April 24, 2008, 09:24:35 PM »

Quote
how do I upgrade?
Just before your POST, some links for a start Huh
And if you had downloaded the Coppermine's package, there's a DOC inside !

PYAP

Logged

҈ Pas de PM please ! ҈
Medievaldragon
Coppermine newbie


Karma: -1
Posts: 2


« Reply #7 on: April 24, 2008, 09:27:29 PM »

Thanks, I am backing up the MySQL right now.
Logged
Hein Traag
Dev Team member
Coppermine addict
****

Karma: 26
Gender: Male
Posts: 1348


A, B, Cpg


WWW
« Reply #8 on: April 24, 2008, 09:38:41 PM »

Since this is an announcement thread it is now closed. Any questions concerning 1.4.18 ? Open your very own thread and ask away  Grin
Logged

Read the documentation and sticky threads. Use the Search function. And always look both ways before crossing the road Wink
Do not PM me unless asked to do so!
Joachim Müller Topic starter
Administrator
Coppermine addict
*****

Karma: 104
Gender: Male
Posts: 38119


aka "GauGau"


WWW
« Reply #9 on: April 25, 2008, 07:18:42 AM »

If you have problems with this update, please use the Update support board. Do not post your issues to this announcement thread - they will be deleted without notice.
Cluttering this thread although the announcement clearly says you mustn't is silly and selfish.
Logged

Don't contact me over PM or email unless I asked you to. Instead: post on the proper board. All unrequested messages will be ignored and your negative karma will no doubt increase!
Like my avatar? Create a free custom avatar just like mine.
Pages: [1]   Go Up
  Send this topic  |  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.082 seconds with 18 queries.