[drupal-devel] Drupal 4.6.3 released (security alert)
The Drupal project has released version 4.6.3 of its open-source content management platform. Drupal 4.6.3 is a maintenance release that fixes problems reported using the bug tracking system. Drupal 4.6.3 also fixes a NEW SECURITY VULNERABILITY which was discovered in the third-party XML-RPC library Drupal uses. An attacker could execute arbitrary PHP code on a target site. Upgrading your existing Drupal sites is highly recommended. As the same bugs are also present in the Drupal 4.5 series, Drupal 4.5.5 is released as well. For detailed information about this release and the security vulnerability, please consult the release announcement at http:// drupal.org/drupal-4.6.3 and read the DRUPAL-SA-2005-004 security advisory at http://drupal.org/files/sa-2005-004/advisory.txt. Kudos to all Drupal contributors who helped to get these releases out, -- Dries Buytaert :: http://www.buytaert.net/
On 15 Aug 2005, at 04:08, Dries Buytaert wrote:
Kudos to all Drupal contributors who helped to get these releases out,
= chx, killes, uwe, clouseau. Thanks guys! Off to bed at 04:20am. Great way to spend a Sunday evening, and to start a Monday morning. ;-) -- Dries Buytaert :: http://www.buytaert.net/
Thanks for your work! The timeline on the release page is very impressive. -Evan On 8/14/05, Dries Buytaert <dries@buytaert.net> wrote:
On 15 Aug 2005, at 04:08, Dries Buytaert wrote:
Kudos to all Drupal contributors who helped to get these releases out,
= chx, killes, uwe, clouseau.
Thanks guys! Off to bed at 04:20am. Great way to spend a Sunday evening, and to start a Monday morning. ;-)
-- Dries Buytaert :: http://www.buytaert.net/
On 8/14/05, Dries Buytaert <dries@buytaert.net> wrote:
For detailed information about this release and the security vulnerability, please consult the release announcement at http:// drupal.org/drupal-4.6.3
That page incorrectly states that xmlrpc-4.6.2.patch will patch Drupal 4.6.2 to 4.6.3. The linked patch only fixes the xmlrpc issues; many other changes were made between 4.6.2 and 4.6.3. -Evan
participants (2)
-
Dries Buytaert -
Evan Heidtmann