Joachim Müller
|
 |
« on: February 26, 2006, 12:46:31 pm » |
|
Hello all, due to the security issues discovered recently that exist in all coppermine versions up to and including cpg1.4.3 (see hotfix thread " Patch for Coppermine 1.4.3 remote code execution - Update NOW!") the coppermine dev team has released cpg1.4.4 as a maintenance release. If you haven't applied the above mentioned hotfix it's mandatory to upgrade your install as soon as possible. Users who already have applied the hotfix are safe against the vulnerability, yet it is still recommended to upgrade to cpg1.4.4, as the maintenance release contains various minor bug fixes that are not security-related. The new package cpg1.4.4 contains the most recent language files as well as improved doumentation. Instructions how to upgrade your coppermine version are included in the documentation as well that comes with the package (inside the docs folder) and that are available online as well (link "documentation") at the top of this page. Download cpg1.4.4: http://prdownloads.sourceforge.net/coppermine/cpg1.4.4.zip?downloadPlease do not reply to this thread for individual support issues, but only with general questions related to the release itself. Joachim - coppermine project manager -
|
|
|
|
« Last Edit: April 21, 2006, 08:10:28 am by GauGau »
|
Logged
|
|
|
|
|
kramme
Coppermine newbie
Posts: 1
|
 |
« Reply #1 on: March 06, 2006, 06:38:55 pm » |
|
GauGau wrote: The new package cpg1.4.4 contains the most recent language files as well as improved doumentation.
Question from Kramme: How near is a danish translation for ver. 1.4.4 ? Do you know anything about a possible danish translater ?
|
|
|
|
|
Logged
|
|
|
|
|
Nibbler
|
 |
« Reply #2 on: March 06, 2006, 06:43:08 pm » |
|
|
|
|
|
|
Logged
|
I don't care about what they say, I won't live or die that way.
|
|
|
|
Tiffany
Coppermine newbie
Posts: 13
|
 |
« Reply #3 on: March 09, 2006, 07:33:00 pm » |
|
just follow the documenation to do the update of my gallery 1.3.5 to 1.4.4, but after I do the updated, it's just a blank page now  You can check my gallery page at www.kvhk-entertainment.com/galleryAny suggestons are really appreciated. Sorry, wrong post. Please delete it for me.
|
|
|
|
« Last Edit: March 09, 2006, 07:44:47 pm by Tiffany »
|
Logged
|
|
|
|
|
Nibbler
|
 |
« Reply #4 on: March 09, 2006, 07:39:18 pm » |
|
Please do not reply to this thread for individual support issues, but only with general questions related to the release itself.
|
|
|
|
|
Logged
|
I don't care about what they say, I won't live or die that way.
|
|
|
|
Chickenkicker
Coppermine newbie
Posts: 11
|
 |
« Reply #5 on: March 10, 2006, 06:53:08 pm » |
|
Quick note, in the fix for 1.4.3 patch for remote code execution it states edit docs/showdocs.php Sorry, but in my install the filename is showdoc.php I edited that file, no showdocs.php in my docs directory... Hope others figured this out..
|
|
|
|
|
Logged
|
|
|
|
|
Tigger88
Coppermine newbie
Posts: 1
|
 |
« Reply #6 on: March 10, 2006, 08:00:50 pm » |
|
I just want to make sure before I download and install this that I am not going to lose everything that is already in my gallery since I am currently using cpg 1.3.3.
|
|
|
|
|
Logged
|
|
|
|
|
Nibbler
|
 |
« Reply #7 on: March 10, 2006, 08:03:52 pm » |
|
There are update instructions provided.
|
|
|
|
|
Logged
|
I don't care about what they say, I won't live or die that way.
|
|
|
|
|
Joachim Müller
|
 |
« Reply #9 on: March 11, 2006, 08:54:28 pm » |
|
using html equivalents like è is not recommended when using utf-8. You could have converted the regular language file to iso8859-1 instead. We appreciate your willingness to contribute, but we can't recommend the usage of the file.
|
|
|
|
|
Logged
|
|
|
|
zamirzamir
Coppermine novice

Posts: 36
|
 |
« Reply #10 on: March 19, 2006, 12:34:59 am » |
|
In the read me file it says
Coppermine as a fresh, stand-alone (non-upgrade) install. (If you are trying to upgrade from a previous installation of coppermine, you already know what to do - RTFM.) Ready?
What if I dont know, please provide a link for UPDATE instractions, I wouldnt want to loose my files out of mistake.
|
|
|
|
|
Logged
|
|
|
|
kegobeer
Dev Team member
   
Gender: 
Posts: 4637
Beer - it does a body good!
|
 |
« Reply #11 on: March 19, 2006, 12:36:51 am » |
|
In the read me file it says
Coppermine as a fresh, stand-alone (non-upgrade) install. (If you are trying to upgrade from a previous installation of coppermine, you already know what to do - RTFM.) Ready?
What if I dont know, please provide a link for UPDATE instractions, I wouldnt want to loose my files out of mistake.
Read the documentation. Complete instructions are provided in every Coppermine release.
|
|
|
|
|
Logged
|
Do not send me a private message unless I ask for one. Make your post public so everyone can benefit.
There are no stupid questions But there are a LOT of inquisitive idiots
|
|
|
|
scrapgranny
Coppermine newbie
Posts: 8
|
 |
« Reply #12 on: March 26, 2006, 08:32:54 pm » |
|
Maybe you could just point us in the right direction to FIND the upgrade instructions because I sure can't find them.
Thanks
|
|
|
|
|
Logged
|
|
|
|
|
Nibbler
|
 |
« Reply #13 on: March 26, 2006, 09:29:35 pm » |
|
Look at the top of your screen, click on the word 'Documentation' and read the section '3.5 Upgrading from cpg1.4.0 (or better) to version cpg1.4.4'
|
|
|
|
|
Logged
|
I don't care about what they say, I won't live or die that way.
|
|
|
|
easykey
Coppermine newbie
Posts: 3
|
 |
« Reply #14 on: March 31, 2006, 02:03:49 pm » |
|
Upgraded to 1.4.4 a couple of weeks ago and my Server Administrators have just called me to say that the new 1.4.4 had a security compromise last night so they closed my web space down!!
|
|
|
|
|
Logged
|
|
|
|
|
Nibbler
|
 |
« Reply #15 on: March 31, 2006, 02:30:01 pm » |
|
You'll have to take that up with them.
|
|
|
|
|
Logged
|
I don't care about what they say, I won't live or die that way.
|
|
|
|
easykey
Coppermine newbie
Posts: 3
|
 |
« Reply #16 on: March 31, 2006, 02:32:05 pm » |
|
Who? My dedicated server guys or Coppermine?
|
|
|
|
|
Logged
|
|
|
|
Joachim Müller
|
 |
« Reply #17 on: March 31, 2006, 04:43:26 pm » |
|
don't discuss your individual issues on this announcement thread. Ask your webhost what the actual issue they claim to be coppermine-related is. Start your own thread on the support board for further discussion, don't clutter this one with unrelated stuff.
|
|
|
|
|
Logged
|
|
|
|
|
easykey
Coppermine newbie
Posts: 3
|
 |
« Reply #18 on: March 31, 2006, 05:21:57 pm » |
|
I'm sorry you feel this thread is irrelevant However, I was advised to update from 1.4.3 to 1.4.4 as this maintenance release was to prevent the compromise we experienced on our servers.
Despite installing the Coppermine maintenance release cpg1.4.4 we have been compromised again
My point is I wondered whether anyone else had experienced security breaches with this release?
I will post up general details of the latest vulnerability when I get them
The reason I posted it here was because this thread is a direct link from the main site - entitled Maintenance release cpg1.4.4 fixes security issues - Update NOW!
|
|
|
|
|
Logged
|
|
|
|
Joachim Müller
|
 |
« Reply #19 on: March 31, 2006, 05:30:36 pm » |
|
I repeat: stop replying to this thread! You just posted unusable complaints like to prevent the compromise we experienced on our servers. - that doesn't say anything. Like I said: start your own thread - I will delete all future replies you make to this one. Post what actually happens, be as detailed as possible, with links, error messages, log details and the whole enchillada.
|
|
|
|
|
Logged
|
|
|
|
|