Due to SA-CONTRIB-2014-012 this module is now unmaintainable.

I for one still use this module in production so I'm volunteering to fix this issue and make a new release.

I will reach out to ebeyrent to point me to the details of the issue here.

Note this is a 6.x issue however as that branch has been removed it cannot be selected here.

Comments

dsnopek’s picture

FYI, this was also a surprise to me and I'm one of the maintainers of Modalframe! I've contacted the security team for details so that I can create a patch.

fenstrat’s picture

Odd that you were not contacted @dsnopek. Nice to hear you're still maintaining this module. Please keep us up-to-date, I can certainly help out if needed.

dsnopek’s picture

@fenstrat: Once they let me in on the issue on security.drupal.org and I post a patch, I'll ask you for review. :-)

Well, I only took the module over last Nov - it's possible they contacted the previous maintainer and then he forgot to tell me about it. Anyway, at this point I'm not worried about that - I just want to get in and fix it!

dsnopek’s picture

@fenstrat: I saw that you were added to the security issue a couple days ago. However, it looks like we've already got a fully reviewed patch ready to go. :-)

dsnopek’s picture

Status: Active » Fixed

The issue has been fixed! We have a good 1.9 release. :-)

fenstrat’s picture

Great work here @dsnopek, much appreciated! Sorry I've been AFK for several days so was of no use here, but many thanks for the fix and the new release.

berliner’s picture

@dsnopek Thanks for taking this module over. I just saw the commit concerning the security issue and realized that I had completely forgotten about that issue. I didn't receive any notifications from the security issue, as I would in normal issue queues here.

Anyway, good to see, that this has finally been fixed!

dsnopek’s picture

@berliner: And thank you for the great fix! :-)

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.