Login  |  Register
HTML5 Icon HTML5 Icon HTML5 Icon
TP on Social Media

Recent

Welcome, Guest. Please login or register.
Did you miss your activation email?

November 28, 2022, 10:37:23 PM

Login with username, password and session length
Members
  • Total Members: 3853
  • Latest: tty456
Stats
  • Total Posts: 193617
  • Total Topics: 21105
  • Online today: 60
  • Online ever: 3540
  • (September 02, 2022, 06:38:54 PM)
Users Online
Users: 0
Guests: 60
Total: 60

Author Topic: For Coppermine Gallery users.  (Read 27837 times)

0 Members and 1 Guest are viewing this topic.

Offline lurkalot

  • Administrator
  • *
  • Posts: 7415
    • Camera Craniums
For Coppermine Gallery users.
« on: May 24, 2010, 04:57:16 PM »
For any Coppermine gallery users,

cpg1.4.27 Security release - upgrade mandatory!

Why was cpg1.4.27 released?

"The release covers a recently discovered XSS vulnerability that allows (if unpatched) a malevolent visitor to include own script routines."

http://forum.coppermine-gallery.net/index.php/topic,65023.0.html
« Last Edit: October 01, 2010, 01:48:43 AM by lurkalot »

Offline lurkalot

  • Administrator
  • *
  • Posts: 7415
    • Camera Craniums
Re: cpg1.4.27 Security release - upgrade mandatory!
« Reply #1 on: June 08, 2010, 01:51:20 AM »
Just to add to this,

The new version of Coppermine 1.5.6 Stable has now been released.

http://forum.coppermine-gallery.net/index.php/topic,65278.0.html

What will happen to 1.4.x?

"With all the new features of 1.5.x the development team have decided that only security fixes will be applied to 1.4.x in the short term. However, there will come a time when 1.4.x will be laid to rest. While we have yet to decide on a firm date for this to happen expect support to be withdrawn in around 6 months. With all the new features that 1.5.x brings we firmly believe most users to want to upgrade long before then."

Offline lurkalot

  • Administrator
  • *
  • Posts: 7415
    • Camera Craniums
Re: cpg1.4.27 Security release - upgrade mandatory!
« Reply #2 on: October 01, 2010, 01:44:01 AM »
A bit behind on this, so just bringing up to date.  :-[

Coppermine 1.5.8 [stable] is released.  August 06, 2010

http://forum.coppermine-gallery.net/index.php/topic,66417.0.html

     Ã¢â‚¬Â¢ Built in Captcha engine
     Ã¢â‚¬Â¢ Built in Watermark engine
     Ã¢â‚¬Â¢ New Upload Interface
     Ã¢â‚¬Â¢ Improved Groups control
     Ã¢â‚¬Â¢ Improved Category Management tool
     Ã¢â‚¬Â¢ Drag and drop sorting of albums
     Ã¢â‚¬Â¢ Improved Search engine
     Ã¢â‚¬Â¢ New core ‘Curve’ theme
     Ã¢â‚¬Â¢ Improved image tagging
     Ã¢â‚¬Â¢ Enhanced plugin engine.

Offline lurkalot

  • Administrator
  • *
  • Posts: 7415
    • Camera Craniums
Re: For Coppermine users.
« Reply #3 on: October 01, 2010, 01:47:56 AM »
Support for 1.4.x to cease soon.

When?

"1st December 2010 is the sad date. From then on we will close all the 1.4.x support forums to new threads."

What do we do as website owners?

"That is your choice. Coppermine 1.4.x will not stop working after that date. Having said that, should you run into any problems you will unfortunately be on your own. Additionally, there will be no security updates available so you run the risk if new exploits are discovered."

Read more here, http://forum.coppermine-gallery.net/index.php/topic,66659.0.html

Offline ZarPrime

  • Friends
  • *
  • Posts: 4653
Re: For Coppermine Gallery users.
« Reply #4 on: October 01, 2010, 10:52:04 AM »
Hmmm, a shame that the new version won't be backward compatible. :P

ZarPrime

Offline lurkalot

  • Administrator
  • *
  • Posts: 7415
    • Camera Craniums
Re: For Coppermine Gallery users.
« Reply #5 on: October 02, 2010, 07:44:39 AM »
Hmmm, a shame that the new version won't be backward compatible. :P

ZarPrime

Jim.  Backward compatible with what?  ???

Offline ZarPrime

  • Friends
  • *
  • Posts: 4653
Re: For Coppermine Gallery users.
« Reply #6 on: October 02, 2010, 07:53:01 AM »
I think I probably misread the announcement.  I was thinking that they were saying that the new version wouldn't work with the old code.  I was probably in a fog the day I wrote that so you should probably just ignore my post. ;)

ZarPrime

Offline lurkalot

  • Administrator
  • *
  • Posts: 7415
    • Camera Craniums
Re: For Coppermine Gallery users.
« Reply #7 on: August 02, 2011, 02:20:48 AM »
cpg 1.5.14 maintenance release - upgrade recommended

The Coppermine development team is releasing an update for Coppermine in order to fix several minor issues. All fixes are not security critical, so if your gallery is running fine with cpg1.5.12 you don't need to upgrade. If you are running an older version than cpg1.5.12, you must update to this latest version as soon as possible because of the security impact!

Why was cpg1.5.14 released?
Since the last release of the cpg1.5.x series (about 7 months ago) a couple of improvements has been added to the svn repository.

Changelog:
  • Fixed username in activation mail (thread)
  • Fixed version number displayed on the index page in the doc
  • Added Norwegian language file (user contribution)
  • Fixed album thumbnail for keyword albums without physical files when link_pic_count is disabled (thread)
  • Use the intermediate picture 'use dimension' setting when resizing full-sized pictures during the upload process
  • Fixed spelling of 'email' in German language files
  • Fixed validation of ImageMagick path in config
  • Added missing jump label 'top_display_media' to theme 'eyeball' (thread)
  • Fixed PHP notices 'Undefined variable' and 'Use of undefined constant' during install step 2 (thread)
  • Fixed some missing icons in help pages (thread)
  • Fixed detection of intermediate-sized pictures when renaming files (thread)
  • Added Serbian language file (user contribution)
  • Fixed embedding of SWF files (thread)
  • Fixed safe_mode check when sending emails
  • Fixed selection of gallery icon for user categories (thread)
  • Fixed display of random album thumbnail in sub-category if album keyword is set (thread)
  • Updated Turkish language file (user contribution)
  • Fixed user manager issue (thread)
  • Fixed several keywords issues (issues with ampersands and spaces, leftover keyword separators) (thread)
  • Fixed valid token issue during logout (thread)
  • Display exact character encoding in config (thread)
  • Fixed permission issue if admin tries to create a personal album (thread)
  • Fixed batch-add issue if no file is selected (thread)
  • Fixed visibility issue when setting an album password with IE (thread)
  • Fixed admin tools format in eyeball theme (thread)
  • Fixed thumbnail pages dropdown list on album list (thread)
  • Adjusted part of documentation to reflect cpg1.5.x code change (thread)
  • Fixed critical error message for meta album 'lastalb' if thumbnail image doesn't exist (thread)
  • Fixed first level album thumbnails if thumbnail image doesn't exist
  • Moved memberlist button to home menu drop-down for theme 'curve' (thread)
  • Added workaround for delayed cookie issue during login (thread)

Offline lurkalot

  • Administrator
  • *
  • Posts: 7415
    • Camera Craniums
Re: For Coppermine Gallery users.
« Reply #8 on: January 11, 2012, 01:36:14 PM »
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.16 or older update to this latest version as soon as possible.

How to update:
Users running versions prior to 1.5.18 should update immediately by downloading the latest version from the download page and following the upgrade steps in the documentation.

Support:
If you have problems with this update, please use the Update support board. Do not post your issues to this announcement thread - your post will be deleted without notice.

Why was cpg1.5.18 released?
The release covers a path disclosure vulnerability. If unpatched, it's possible to generate an error that will reveal the full path of the script. A remote user can determine the full path to the web root directory and other potentially sensitive information.

Additionally, cpg1.5.18 includes fixes for the following non-security related issues:
  • Added plugin hook 'upload_file_name'
  • Add default values on 'onlinestats' installation to avoid weird dates right after plugin installation (thread)
  • Updated Arabic language file (user contribution)
  • Fixed simple upload process when users can just upload to their personal gallery (thread)
  • Added upload button after each album name in album manager
  • Added anchors on plugin manager
  • Fixed infinite loop for delayed cookie issue workaround (thread)
  • Disallow dots in cookie name (thread)
  • Fixed issue with very big 'Max size for uploaded files' values (thread)
  • Fixed album thumbnails for public albums in 'My gallery' view for regular users
  • Fixed clickable keywords with spaces (thread)
  • Fixed critical error for 'lasthits' meta album (thread)
  • Fixed misleading error message when uploading files that exceed the file size limit with the simple upload form (thread)
  • Added hidden feature "Create sub-directory named according to the album ID in users' upload directories during HTTP upload"
  • Use selected album thumbnail for 'lastup' meta album (thread)
  • Create user album in personal gallery when user is created via the user manager (thread)
  • Added captcha for ecards feature (thread)
  • Fixed a potential path disclosure vulnerability in core plugin configuration files
  • Updated date/time formats in English (British) language file (thread)
  • Updated header information to reflect new year

The Coppermine Team

Offline lurkalot

  • Administrator
  • *
  • Posts: 7415
    • Camera Craniums
Re: For Coppermine Gallery users.
« Reply #9 on: March 29, 2012, 04:20:50 PM »
cpg1.5.20 Security release - upgrade mandatory!

The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.18 or older update to this latest version as soon as possible.

Why was cpg1.5.20 released?
The release covers several path disclosure vulnerabilities. If unpatched, it's possible to generate an error that will reveal the full path of the script. A remote user can determine the full path to the web root directory and other potentially sensitive information.
Furthermore, the release covers a recently discovered XSS vulnerability that allows (if unpatched) a malevolent visitor to include own script routines under certain conditions.

Additionally, cpg1.5.20 includes fixes for the following non-security related issues:
  • Disabled possibility to move albums to root level of user category (thread)
  • Fixed broken IP address lookup (thread)
  • Fixed email validation for registration process (thread)
  • Updated Serbian language file (user contribution)
  • Changed status in credits section to 'retired'
  • Updated Italian language file (user contribution)
  • Re-added 'search by owner name' checkbox to search form (thread, thread)
  • New feature: display only the uploaded files from the last queue after flash upload (thread)
  • Fixed behavior of "Show first level album thumbnails in categories" setting (thread)
  • Added plugin hook 'theme_album_params'
  • Fixed quota bar in user manager for secondary group memberships (thread)
  • Display default groups "Administrators" and "Registered" on modify user page (thread)
  • Moved code from usermgr.php to function 'cpg_get_groups'
  • Added Opera compatibility for rounded corners to theme 'curve' (thread)
  • Fixed error message at "Edit file information" form (thread)
  • Updated EXIF library (thread)
  • Fixed clickable keywords in file information box at intermediate view (thread)
  • Fixed search results when searching for specific characters (thread)
  • Fixed error message when activating more than one user in the user manager (thread)
  • Fixed different gallery behavior for register_globals on/off setting (thread)

Offline lurkalot

  • Administrator
  • *
  • Posts: 7415
    • Camera Craniums
Re: For Coppermine Gallery users.
« Reply #10 on: February 16, 2017, 12:37:40 AM »
The Coppermine development team is releasing a security update for Coppermine in order to counter recently discovered vulnerabilities. It is important that all users who run version cpg1.5.44 or older update to this latest version as soon as possible.

How to update:
Users running versions prior to 1.5.46 should update immediately by downloading the latest version from the download page and following the upgrade steps in the documentation.

Support:
If you have problems with this update, please use the Update support board. Do not post your issues to this announcement thread - your post will be deleted without notice.

Why was cpg1.5.46 released?
The release covers a recently discovered directory traversal vulnerability that allows (if unpatched) a malevolent visitor to access restricted directories under certain conditions.

Thanks to Matthew Hickey from My Hacker House for discovering the vulnerability.


The Coppermine Team