Gossamer Forum
Home : Products : Gossamer Links : Discussions :

re: Security Fix - Official Notice

Quote Reply
re: Security Fix - Official Notice
Hi,

I got this email from Alex this morning:

Code:
During internal testing today, we recently found a security hole affecting most of our new products, specifically:

Links SQL 2.0.3+
DBMan SQL 2.0.0 Beta1+
Gossamer Mail 2.0.1+
FileMan 2.0.0 Beta1+

If you are using any of these products, it's very important that you apply the security fix immediately.
and with regard to LinksSQL he says...

Code:
Version 2.0.4 has been updated in the download area to fix the security problem. Also included is a Links-SQL2.0.4-Security file which has the two files you can just replace if you've made extensive changes to an existing installation.
I downloaded the patch for LinksSQL2.0.3 but when I read the instructions it just says that you have to replace your Links.pm and Template.pm files. The problem is that I have customized these extensively.

Is there anyway of finding out the exact lines that need changing? This would help me (and others I assume).

Thanks

JeffB

Quote Reply
Re: re: Security Fix - Official Notice In reply to
Hi,

Drop an email to security@gossamer-threads.com with ssh/telnet access and where it's installed and we can patch it for you.

Cheers,

Alex

--
Gossamer Threads Inc.
Quote Reply
Re: re: Security Fix - Official Notice In reply to
I would prefer do it myself. Please either post the changes need on this thread or email them to me.

JeffB

Quote Reply
Re: re: Security Fix - Official Notice In reply to
Posting the changes publically exposes the hole, and turns a non-exploited bug into an exploited one.

Hopefully, people downloading the patch realize that -- and keep it quiet.

PUGDOGŪ Enterprises, Inc.
FAQ:http://LinkSQL.com/FAQ
Plugins:http://LinkSQL.com/plugin