it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: "CiviCRM" <info AT civicrm.org>
- To: <it-securitynotifies AT lists.piratenpartei.de>
- Subject: [IT-SecNots] CiviCRM Security Advisories - 4.4.6, 4.2.17LTS
- Date: Wed, 02 Jul 2014 03:39:01 -0700
- List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
- List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>
There has been a security advisory for CiviCRM. We recommend you immediately upgrade to one of the following versions:
Read the security advisories for details:
- https://civicrm.org/advisory/civi-sa-2014-002-risk-information-disclosure-anonymous-users
- https://civicrm.org/advisory/civi-sa-2014-003-insecure-handling-profile-settings
To receive future CiviCRM security notices, subscribe to notifications.
In addition, CiviCRM 4.4.6 contains 30 fixes, making it the most stable version of 4.4 available. Upgrading now can save you a lot of troubleshooting later.
» View all issues fixed in the 4.4.6 release.
4.2 LTS Regression Advisory
The latest version of the 4.2 LTS fixes a security hole but contains a regression that affects individuals filling in contribution pages on behalf of organisations IF they have more than one employer. If they make an error in filling out the form, the form they see as a result contains fields for each employer.
We recommend you upgrade to secure your site. If this edge case affects your organisation you should look at upgrading directly to 4.4 or contract someone to work further on this. The 4.4 patch is complex & the code involved has changed between versions and the 4.2 LTS is now winding down - hence we were not able to secure the LTS without this edge case regression within the amount of time people were prepared to donate.
United States
- [IT-SecNots] CiviCRM Security Advisories - 4.4.6, 4.2.17LTS, CiviCRM, 02.07.2014
Archiv bereitgestellt durch MHonArc 2.6.19.