Important security alert for all versions of StatusNet
This morning at 9AM we received notice of a security vulnerability in all versions of the StatusNet software. The StatusNet team has verified the vulnerability and identified a separate but similar vulnerability in another block of code. For these reasons, we've issued Security Alert 0000002 and made new versions of all three branches of our software available for download.
- New stable version: StatusNet 0.8.3
- New beta version: StatusNet 0.9.0beta5
We've also issued a new version of the old branch, 0.7.x, to service users who haven't yet upgraded to the stable version. We opted not to upgrade the name of this version to avoid any unnecessary effort on the part of upgraders.
- New old version: Laconica 0.7.5
We highly recommend that all users of the StatusNet software upgrade to a newer version immediately.
Thanks to Mark Piper for identifying the vulnerability and alerting the StatusNet development team. The vulnerability is in the online help documentation feature. Carefully crafted URLs provided by the attacker can force the Web server to serve arbitrary files from the filesystem. An attacker can use this vulnerability to retrieve important security files from the system. More information at Security Alert 0000002.



Comments
Post new comment