drupal 6.0-rc3

Security update
Bug fixes
Insecure

For more information on this release candidate and about compatible modules, themes and translations, refer to: http://drupal.org/drupal-6.0-rc3

This release candidate fixes a security vulnerability. Those running the previous release candidate are urged to upgrade immediately. For more details, please see the security announcement:

In addition to this security vulnerability, the following bugs have been fixed since the first release candidate:

  • #208427 report by Pancho, patch by dvessel: strpos() parameters were flipped in color module, resulting in bad colors
  • #208197 by dvessel: back to cloning the table header only in tableheader.js (fixes radio button issues and Safari 2 crashing)
  • - Patch #210140 by dww: fixed code comment: 'default_major' is now deprecated in favor of 'supported_majors'.
  • - Patch #209236 by traxer: added a validation function for the poll form.
  • - Patch #206495 by jvandyk: improved consistency of trigger descriptions.

securesite 5.x-1.1

Security update

Security update, see #216019, SA-2008-011 - Securesite - Access bypass.

securesite 4.7.x-1.1

Security update

Security update, see #216019, SA-2008-011 - Securesite - Access bypass.

comment_upload 4.7.x-0.1

Security update

The release fixes an arbitrary file upload issue. See SA-2008-015 for details.

Changes since DRUPAL-4-7:

comment_upload 5.x-0.1

Security update

This is the first release of comment_upload as a 0.1 version.

The release fixes an arbitrary file upload issue. See SA-2008-015 for details.

Changes since DRUPAL-5:

openid 5.x-1.1

Security update
Insecure

* #216022 (SA-2008-016) - OpenID - Incorrect claimed_id returned for OpenID 2.0
(reported by johnnysxip)
* other minor OpenID 2.0 compliance fixes

Pages

Subscribe with RSS Subscribe to RSS - Security update