This is the Lussumo Swell Blog.

Stay up to date with the development of Lussumo software
like Vanilla, and the Filebrowser.

 

Feeds

This blog is still in alpha and is missing many important features. Sadly, one of those features is RSS feeds. Patience is a virtue.

What is Lussumo?

Lussumo (rhymes with "bus-you-toe") means "love you more". Mark O'Sullivan started Lussumo in the late 90's as a custom-built web forum for designers and programmers. Now Lussumo is a place where you can get free, open-source software for the web.

Our Products

Vanilla
Filebrowser
Swell (0.0.1) is a product of Lussumo. More Information: Documentation, Community Support.
Vanilla 1.0.3 Released
Mark
Dec 4th 2006
Security, Release, Vanilla
Yet another location for the register_globals attack has been discovered in the Vanilla core. If you are upgrading from the Vanilla 1.0.2 release, you don't need to download the new package to apply the patch. Just add the following code to the second line of your conf/extensions.php file:

if (!defined('IN_VANILLA')) exit();

I am also putting all extension authors on alert: If any of your extensions include external files, you need to add the line above to your extension files. I will be contacting all of the extension authors by email later today with more detailed instructions.

Thanks go out to Dinoboff for locating the additional security holes.

11 comments

Jump to Latest
Ben
Dec 4th 2006
I thought that file got wiped every time you added/removed an extension?
Waterskiaddict
Dec 4th 2006
Thanks for the heads up yet again...
Mark
Dec 4th 2006
@Ben - it used to in a previous revision. Now it only removes or adds the necessary lines to enable or disable an extension. So the installer/upgrader now adds the necessary line of code to prevent the attack and the extension manager just leaves it there. If, however, you aren't doing a fresh install or upgrading from 0.9.2, then you have to add it manually.
Dave
Dec 14th 2006
This post read like all I need to do to a 1.0.2 release is add that line to the file, yet if I grep the source for that define it doesn't show up, and of course nothing works.

Am I miss understanding the post, do I need to download and apply the patch first?
Mark
Dec 14th 2006
The entry says "If you are upgrading from the Vanilla 1.0.2 release".

If you are upgrading from some other release, then you'll need to do a full upgrade - instructions are included in the package.

The reason a grep doesn't show any changes is because Vanilla doesn't include your conf/*.php files by default. It creates them automatically when you do your install. If, however, you already have Vanilla installed, you will have to add the line manually.
Dec 18th 2006
Would have been nice for this blog's RSS feed to be working for automatic notification for security issues like this. Just saying. Of course, I'm at 1.0.3. =)
Mark
Dec 18th 2006
@Ernie - I agree. I do, however, have RSS on the community forum, and that feed should give anyone who's interested a much more up-to-date glance at what's going on with both Vanilla and it's add-ons.

If it were a perfect world, I'd have time to finish Swell, Fix up the addons site so it also has comments and RSS feeds, AND get all of the Vanilla changes and updates into place.

But sadly, this is reality.
Jan 6th 2007
I am using Vanilla 1.0.1 and I recently applied the patch manually. The result was Vanilla stopped working at all - it returns only blank files, instead of HTML.
Any idea why?
Mark
Jan 6th 2007
Anyone having problems with the upgrade should go to lussumo.com/community for help.
Aug 30th 2007
<a href= http://hardbabes-com.zovyre.cn >portofino bay</a> <a href= http://aspd-net-therapeutic-massage.zovyre.cn >1998 chev malibu thief warning</a> <a href= http://myfriendlydating-com.zovyre.cn >dugan racing</a> <a href= http://clubxxx-it.zovyre.cn >simmons college professional development</a> <a href= http://iamthebutterflyman-com.zovyre.cn >clyde yates teacher</a> <a href= http://chanalbion-com.zovyre.cn >hope center in jercity city</a> <a href= http://fantasies-freesexlist-net.zovyre.cn >cw shredder</a> <a href= http://campgear-ca.zovyre.cn >proforma</a> <a href= http://fresh-women-com-password.zovyre.cn >rate your professor</a> <a href= http://stbarnabasfalmouth-org.zovyre.cn >selegiline patch</a>
Jan 1st 2008
<a href= http://zizefela.newmail.ru >chrysler</a> <a href= http://kotutiv.newmail.ru >devildogs.info platoon charlie</a> <a href= http://zacilos.newmail.ru >coupons dinner</a> <a href= http://vehixyna.newmail.ru >malfeasance - definition</a> <a href= http://zabiwi.newmail.ru >sushi lahaina hi</a> <a href= http://jefyfu.newmail.ru >record jurenal conn.</a> <a href= http://hikiti.newmail.ru >charlene davis kennedy kreiger baltimore md</a> <a href= http://zelupyx.newmail.ru >airshow</a> <a href= http://jorira.newmail.ru >unitysound</a> <a href= http://jimiwigy.newmail.ru >blue book</a>

Post Your Comments

Name
Email
Url
Comments