Security release JFusion 1.5.5

Moderator: sil3nt

Forum rules
Please post all the bugs you encounter on our issue tracker.

Security release JFusion 1.5.5

Postby mariusvr on Sun Feb 06, 2011 4:53 am

Hello JFusion Fans,<

It was brought to our attention yesterday that jfusion could have a vulnerability after a helpful jfusion user noticed a failed attack in their server logs. We take security extremely serious at JFusion and within 24 hours of being notified this vulnerability is fixed in JFusion. Many thanks to the people on three different continents that have worked around the clock for this fix.

Only people that run "frameless integration" using the phpbb3, smf, dokuwiki and gallery2 are affected if their apache webserver allows for execution commands frequently used by hackers, this then allowed a hacker to expose other vulnerable software on your server. The issue was with regex replace command used for frameless mode, that allowed evaluations of expressions inserted into URLs on some pages. JFusion now no longer uses this type of regex expression in our code base.

We strongly recommend that you upgrade to JFusion 1.5.5 immediately to prevent hackers using JFusion to find other vulnerabilities on only some servers with frameless mode enabled. We sincerely apologise for any inconvenience. Our commitment to security is strong, as we fix any issue within 24 hours

You can update your jfusion installation with a single click through the jfusion version checker, or you can manually download JFusion 1.5.5 from our download section on our website

We are nearing the release of JFusion 1.6 beta after our first alpha release. Many thanks to all the people that help test JFusion on the new Joomla 1.6.0. Almost all outstanding issues have been fixed and we will announce when JFusion 1.6 is ready for beta testing

Thank you for your support, Marius
User avatar
mariusvr
Developer
Developer
 
Posts: 3131
Joined: Sun Jan 13, 2008 9:55 am
Location: Perth, Western Australia

Re: Security release JFusion 1.5.5

Postby Peter_AUS on Sun Feb 06, 2011 10:33 pm

Need to change it on the front page on the right for the download link.

Thanks for the email out, not sure if it affected me or not, but updated anyway.
Regards,

Peter
User avatar
Peter_AUS
Official Tester
Official Tester
 
Posts: 526
Joined: Fri Feb 08, 2008 9:10 am
Location: Carlingford NSW Australia

Re: Security release JFusion 1.5.5

Postby fanno on Mon Feb 07, 2011 10:12 am

it is actually 1.5.5, the image have just not been updated yet!
Fanno
_________________________________
Developer
Specialist on SMF, DokuWiki , Mantis, Eventum, Mediawiki, Universal plugin


Review us at!
http://extensions.joomla.org/extensions/3723/details
User avatar
fanno
Developer
Developer
 
Posts: 7680
Joined: Wed Jan 07, 2009 4:38 pm
Location: Denmark, Copenhagen

Re: Security release JFusion 1.5.5

Postby Peter_AUS on Mon Feb 07, 2011 10:10 pm

Thanks, just thought people might get a bit confused with the different indicators for latest release.
Regards,

Peter
User avatar
Peter_AUS
Official Tester
Official Tester
 
Posts: 526
Joined: Fri Feb 08, 2008 9:10 am
Location: Carlingford NSW Australia

Re: Security release JFusion 1.5.5

Postby fanno on Mon Feb 07, 2011 11:41 pm

Peter_AUS wrote:Thanks, just thought people might get a bit confused with the different indicators for latest release.

i understand i just don't have time to update the pic
Fanno
_________________________________
Developer
Specialist on SMF, DokuWiki , Mantis, Eventum, Mediawiki, Universal plugin


Review us at!
http://extensions.joomla.org/extensions/3723/details
User avatar
fanno
Developer
Developer
 
Posts: 7680
Joined: Wed Jan 07, 2009 4:38 pm
Location: Denmark, Copenhagen

Re: Security release JFusion 1.5.5

Postby Peter_AUS on Wed Feb 09, 2011 12:21 am

It has been updated.
Regards,

Peter
User avatar
Peter_AUS
Official Tester
Official Tester
 
Posts: 526
Joined: Fri Feb 08, 2008 9:10 am
Location: Carlingford NSW Australia

Re: Security release JFusion 1.5.5

Postby fanno on Wed Feb 09, 2011 6:49 am

Peter_AUS wrote:It has been updated.

ya i know =P but i change it so it is no longer a image with version number in it.. now it is a blank image with text floating over it.

saves us time
Fanno
_________________________________
Developer
Specialist on SMF, DokuWiki , Mantis, Eventum, Mediawiki, Universal plugin


Review us at!
http://extensions.joomla.org/extensions/3723/details
User avatar
fanno
Developer
Developer
 
Posts: 7680
Joined: Wed Jan 07, 2009 4:38 pm
Location: Denmark, Copenhagen

Re: Security release JFusion 1.5.5

Postby Webcie on Tue Mar 01, 2011 3:18 pm

Any update on the 1.6 progress? 14 februari is long ago and I haven't found any news on the progress of it.
User avatar
Webcie
JFusion Newbie
JFusion Newbie
 
Posts: 3
Joined: Tue Mar 01, 2011 3:16 pm

Re: Security release JFusion 1.5.5

Postby zaminur143 on Thu Mar 17, 2011 4:16 am

We strongly recommend that you upgrade to JFusion 1.5.5 immediately to prevent hackers using JFusion to find other vulnerabilities on only some servers with frameless mode enabled. We sincerely apologise for any inconvenience. Our commitment to security is strong, as we fix any issue within 24 hours

We are nearing the release of JFusion 1.6 beta after our first alpha release. Many thanks to all the people that help test JFusion on the new Joomla 1.6.0. Almost all outstanding issues have been fixed and we will announce when JFusion 1.6 is ready for beta testing

Thanks Marius, I would have to upgrade 1.5.5 immediately. Happy to get your suggestion. I am wondering about JFusion 1.6. Is it more reliable?
Zaminur
User avatar
zaminur143
JFusion Newbie
JFusion Newbie
 
Posts: 4
Joined: Wed Mar 16, 2011 8:16 pm

Re: Security release JFusion 1.5.5

Postby fanno on Thu Mar 17, 2011 11:14 am

zaminur143 wrote:
We strongly recommend that you upgrade to JFusion 1.5.5 immediately to prevent hackers using JFusion to find other vulnerabilities on only some servers with frameless mode enabled. We sincerely apologise for any inconvenience. Our commitment to security is strong, as we fix any issue within 24 hours

We are nearing the release of JFusion 1.6 beta after our first alpha release. Many thanks to all the people that help test JFusion on the new Joomla 1.6.0. Almost all outstanding issues have been fixed and we will announce when JFusion 1.6 is ready for beta testing

Thanks Marius, I would have to upgrade 1.5.5 immediately. Happy to get your suggestion. I am wondering about JFusion 1.6. Is it more reliable?


lf 1.6 is getting there but it is not 100% ready yet
Fanno
_________________________________
Developer
Specialist on SMF, DokuWiki , Mantis, Eventum, Mediawiki, Universal plugin


Review us at!
http://extensions.joomla.org/extensions/3723/details
User avatar
fanno
Developer
Developer
 
Posts: 7680
Joined: Wed Jan 07, 2009 4:38 pm
Location: Denmark, Copenhagen

Next

Return to Gallery 2

Who is online

Users browsing this forum: No registered users and 1 guest