Koby Posted December 18, 2006 Report Share Posted December 18, 2006 Simple Machines is happy to announce the release of SMF 1.1.1. Unfortunately a few bugs crept into the final release of 1.1 which this patch addresses - in addition an issue was reported with both SMF 1.0 and 1.1 which may allow someone to take advantage of a security hole within Internet Explorer to exploit a forum. This release closes this potential hole. Note users who are still running SMF 1.0.9 (Or earlier) and are not ready to upgrade to SMF 1.1 should see this topic for information on patching the SMF 1.0.x line. A full list of fixes is as follows:Fixed potential XSS vulnerability for users of Internet Explorer. (Reported by Jessica Hope and rotwang)Changed the way SMF logs IP addresses to make it harder for someone to bypass banning.Fixed bug in BBC parsing that could cause an error for people with special characters in their user name on certain versions of PHP.Fixed apostrophes in smiley location path causing a database error.Fixed usage of an array before it was declared causing issues for bridges.Fixed Personal Message labels not being properly restricted to the current member.Fixed search sometimes returning no results when it should have done.The sticky check box in prune boards would alternate when it shouldn't have done.Send announcements out in slightly smaller chunks.Well it appears there was some things that slipped through the v1.1 final release. Thus they had to release a quick update to fix those issues. And well I upgraded as soon as I found out about it (which they emailed me). And well upgrading could not have been any easier. I simply had to go to the admin cp => packages, and then it downloaded and installed it all on its own. And since we had no modifications done or anything yet, it didn't mess any modifications up (Thats one thing I hate about Modifications LOL). Link to comment Share on other sites More sharing options...
VincentsLucrecia Posted December 19, 2006 Report Share Posted December 19, 2006 Hm, it seems not too much was changed around. Glad that you upgraded it right away, Koby! Link to comment Share on other sites More sharing options...
Koby Posted December 19, 2006 Author Report Share Posted December 19, 2006 Yeah it didn't change anything really, it was just a bug and exploit updates. Meaning it just fixed a few problems. Link to comment Share on other sites More sharing options...
-PHXN- New001 Posted December 20, 2006 Report Share Posted December 20, 2006 If it means making our forums safer, I'll take an update anyday Link to comment Share on other sites More sharing options...
Recommended Posts