Security update

finder 7.x-2.0-alpha8

Download Size md5 hash
finder-7.x-2.0-alpha8.tar.gz 61.4 KB 43644b37426ae38bf4482798c55f60f0
finder-7.x-2.0-alpha8.zip 79.75 KB 59980155be14f3690a36901a96f80240
Official release from tag: 7.x-2.0-alpha8
Last updated: February 8, 2012 - 06:00

Addresses SA-CONTRIB-2012-017.
Issue #1383918 by Georgii: Only set false token with logged in user.
Issue #11394130 by danielb: Added a #title_display setting.
Issue #1407880 by danielb: Compatibility with certain block views.
Issue #1414108 by kervi: Syntax error in element ui.
Issue #1414108 by kervi, danielb: Title display not saved.

finder 6.x-1.26

Download Size md5 hash
finder-6.x-1.26.tar.gz 59.58 KB 1b7c4608e4a28d2c800fd98866f47a52
finder-6.x-1.26.zip 75.02 KB 8a9c409150a9382d030e1b6b7d533fe4
Official release from tag: 6.x-1.26
Last updated: February 8, 2012 - 06:00

Addresses SA-CONTRIB-2012-017.
Issue #1420782 by danielb: Performance issue with optionwidgets.

revisioning 6.x-3.14

Download Size md5 hash
revisioning-6.x-3.14.tar.gz 49.4 KB f5a092e0ad0a79663068487e21e9ca3d
revisioning-6.x-3.14.zip 65.64 KB 9090c0ddb4e129d50fbd15e3a31130cf
Official release from tag: 6.x-3.14
Last updated: February 7, 2012 - 10:10

SA-CONTRIB-2012-018 - Revisioning - Cross Site Scripting

drupal 7.11

Download Size md5 hash
drupal-7.11.tar.gz 2.66 MB e9857e1749762367d7631d74cc6564a7
drupal-7.11.zip 3.08 MB 687258ef31de9f5827779c33e594c25f
Official release from tag: 7.11
Last updated: February 1, 2012 - 22:11

Important!! It was discovered post-release that this version of Drupal only includes bug fixes from Drupal 7.9, not Drupal 7.10! Users are encouraged to use Drupal 7.12 instead. Discussion is happening at #1430404: Drupal 7.11 is missing all the bug fixes from Drupal 7.10

Maintenance and security release of the Drupal 7 series. Only fixes for security vulnerabilities have been committed. New features are only being added to the forthcoming Drupal 8.0 release.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included. For additional bugfixes, see Drupal 7.12 released alongside Drupal 7.11.

drupal 6.23

Download Size md5 hash
drupal-6.23.tar.gz 1.05 MB e3e752702d466a1babcb2a827d272424
drupal-6.23.zip 1.21 MB 1d42f25d8336c4afc4f297ef828ddff6
Official release from tag: 6.23
Last updated: February 1, 2012 - 22:10

The twentythird maintenance and security release of the Drupal 6 series. Only fixes for security vulnerabilities have been committed. New features are only being added to the forthcoming Drupal 8.0 release.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included. For additional bugfixes, see Drupal 6.24 released alongside Drupal 6.23.

forward 7.x-1.3

Download Size md5 hash
forward-7.x-1.3.tar.gz 26.88 KB 136b16da0beac72119815a762809f48f
forward-7.x-1.3.zip 29.61 KB e80890fe38656d669e478a83298e7351
Official release from tag: 7.x-1.3
Last updated: February 1, 2012 - 02:31

Release notes:

Add access control and flood control to prevent access bypass and CSRF vulnerabilities, plus additional minor fixes.

#251696: "Popular content" includes nodes user does not have access to
#1355598: Subject & body not changed

The upgrade is "code only" and does not require running the database update script.

IMPORTANT: Administrators of sites that rely on the Dynamic Block access bypass to operate correctly need to visit the Forward configuration page and explicitly select the Dynamic Block Access Control bypass option after upgrading. This should be rare, so most site administrators can simply upgrade the module without the need for additional configuration.

Subscribe with RSS Syndicate content
nobody click here