Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 111439 - Joomla! 1.0.3 Security Release [VERSION BUMP]
Summary: Joomla! 1.0.3 Security Release [VERSION BUMP]
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Linux bug wranglers
URL: http://www.joomla.org/content/view/33...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-11-03 20:06 UTC by Peter
Modified: 2005-11-03 21:29 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Peter 2005-11-03 20:06:23 UTC
1.0.3 Chang Log

Contains following Security Fixes
Medium Level Threat
 * Fixed SQL injection bug in content submission (thanks Dead Krolik)

Low Level Threat
 * Fixed securitybug in admin.content.html.php when 2 logged in and try to edit
   the same content
 * Fixed Search Component flooding, by limiting searching to between 3 and 20 
   characters
 * Fixed artf1405 : Joomla shows Items to unauthorized users

-------

14-Oct-2005 Rey Gigataras
 # Fixed edit icon not showing on frontpage
 # Fixed artf1553 : database.php fails to pass resource id into
   mysql_get_server_info() call
 # Fixed artf1560 : Install1.php doesn't enforce rule against old_ table prefix

13-Oct-2005 Andy Miller
 # Fixed artf1504 : rhuk_solarflare_ii Template | Menus with " not displaying
   correctly

13-Oct-2005 Rey Gigataras
 # Fixed duplicated module creation in install
 # Fixed XHTML issue in rss feed module
 # Fixed XHTML issue in com_search
 # Fixed artf1550 : Properly SEFify com_registration links 
 # Fixed artf1533 : rhuk_solarflare_ii 2.2 active_menu
 # Fixed artf1354 : Can't create new user
 # Fixed artf1433 : Images in Templates
 # Fixed artf1531 : RSS Feed showing wrong livesite URL

12-Oct-2005 Marko Schmuck
 * Fixed securitybug in admin.content.html.php when 2 logged in and try to edit
   the same content 
   [ Low Level Security Bug ]

12-Oct-2005 Johan Janssens
 # Fixed artf1266 : gzip compression conflict
 # Fixed artf1453 : Weblink item missing approved parameter
 # Fixed artf1452 : Error deleting Language file
 # Fixed artf1373 : Pagination error

12-Oct-2005 Rey Gigataras
 ^ Core now automatically calculates the offset between yourself and the server
 # Fixed bug in Global Config param `Time Offset`
 # Fixed artf1414 : Missing images in HTML_toolbar
 # Fixed artf1513 : PDF format does not work at version 1.0.2

11-Oct-2005 Rey Gigataras
 * Fixed Search Component flooding, by limiting searching to between 3 and 20
   characters 
   [ Low Level Security Bug in 1.0.x ]
 ^ Blog - Content Category Archive will no longer show dropdown selector 
   when coming from Archive Module
 # Fixed artf1470 : Archives not working in the front end
 # Fixed artf1495 : Frontend Archive blog display
 # Fixed artf1364 : TinyMCE loads wrong template styles
 # Fixed artf1494 : Template fault in offline preview
 # Fixed artf1497 : mosemailcloak adds trailing space
 # Fixed artf1493 : mod_whosonline.php

09-Oct-2005 Rey Gigataras
 * Fixed SQL injection bug in content submission [ Medium Level Security Bug  ]
 * Fixed artf1405 : Joomla shows Items to unauthorized users [ Low Level
   Security Bug in 1.0.2 ]
 # Fixed artf1454 : After update email_cloacking bot is always on
 # Fixed artf1447 : Bug in mosloadposition mambot
 # Fixed artf1483 : SEF default .htaccess file settings are too lax
 # Fixed artf1480 : Administrator type user can loggof Super Adminstrator
 # Fixed artf1422 : PDF Icon is set to on when it should be off
 # Fixed artf1476 : Error at "number of Trashed Items" in sections
 # Fixed artf1415 : Wrong image in editList() function of mosToolBar class

08-Oct-2005 Johan Janssens
 # Fixed artf1384 : tinyMCE doesnt save converted entities

07-Oct-2005 Andy Miller
 # Fixed tabpane css font issue

07-Oct-2005 Johan Janssens
 # Fixed artf1421 : unneeded file includes\domit\testing_domit.php

07-Oct-2005 Andy Stewart
 # Fixed artf1382 : Added installation check to ensure "//" is not generated
   via PHP_SELF
 # Fixed artf1439 : Used correct ErrorMsg function and updated javascript       
   redirect to remove POSTDATA message
 # Fixed artf1400 : Added a check of $other within com_categories to skip 
   section exists check if set to "other"

05-Oct-2005 Robin Muilwijk
 # Fixed artf1366 : Typo in admin, Adding a new menu item - Blog Content 
   Category

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2005-11-03 21:29:10 UTC
joomla-1.0.3 (23 Oct 2005)

  23 Oct 2005; Renat Lumpau <rl03@gentoo.org> -joomla-1.0.1.ebuild,
  +joomla-1.0.3.ebuild:
  Version bump wrt bug #108621.