Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 317299 - =www-apps/joomla-1.5.16: Two vulnerabilities
Summary: =www-apps/joomla-1.5.16: Two vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://www.joomla.org/announcements.html
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-04-26 11:46 UTC by Jasper Jaklofsky
Modified: 2010-05-03 11:26 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jasper Jaklofsky 2010-04-26 11:46:22 UTC
IMPORTANT UPDATE EFFECTIVE 25 APRIL 2010: Version 1.5.16 contains two serious bugs that will affect your site if you use a version of PHP prior to 5.2 or if you have the Session Handler parameter set to None in Global Configuration. To correct these issues, version 1.5.17 is scheduled to be released on 27 April 2010. If you haven't already upgraded to version 1.5.16, you may wish to wait for version 1.5.17 instead.

Reproducible: Always
Comment 1 Olivier Huber 2010-04-30 23:11:10 UTC
Thanks for the warning.
I don't think that Joomla 1.5.16 will ever hit the tree.
Joomla 1.5.17 should enter it in the next days.

Comment 2 Jasper Jaklofsky 2010-05-01 06:17:25 UTC
Joomla 1.5.16 was already in the tree. 1.5.17 has been released.
Comment 3 Olivier Huber 2010-05-01 06:23:34 UTC
(In reply to comment #2)
> Joomla 1.5.16 was already in the tree. 1.5.17 has been released.
> 
Opps, you're right.
I asked fauli to bump it yesterday.
Comment 4 Tobias Heinlein (RETIRED) gentoo-dev 2010-05-01 12:05:50 UTC
Okay, thanks for the report.

As .16 fixed a few other vulnerabilities, please don't forget to remove .15 and .16 after bumping to .17.
Comment 5 Christian Faulhammer (RETIRED) gentoo-dev 2010-05-03 09:47:22 UTC
(In reply to comment #4)
> Okay, thanks for the report.
> 
> As .16 fixed a few other vulnerabilities, please don't forget to remove .15 and
> .16 after bumping to .17.

 Sorry guys, my laptop was stolen last week and I am not able to do any Gentoo related work for the next couple of weeks.  As I announced it to the teams I work in I forgot security.  Bump should be straightforward.
Comment 6 Tobias Heinlein (RETIRED) gentoo-dev 2010-05-03 11:26:19 UTC
Bumped. ~3 → noglsa.