نسخه نهایی phpBB 3.2.4 فارسی منتشر شد + دانلود (آپدیت امنیتی)
توضیحات:
سلام سر انجام نسخه جدید phpBB به شماره ورژن 3.2.4 با حل بعضی مشکلات و باگ ها به خصوص باگ امنیتی مربوط به ImageMagick منتشر شد. توصیه موکد این است که این آپدیت را انجام دهید تا مشکلی برای تالا شما پیش نیاید.
We are pleased to announce the release of phpBB 3.2.4 "Bertie's ‘stache". This version is a maintenance and security release of the 3.2.x branch which fixes one security issue and various issues reported in previous versions.
The security issue was discovered with a new exploitation technique called Phar deserialization. An attacker with control over a founder admin account could escalate to remote code execution by abusing PHP’s default unserialization of metadata in Phar files. More information about this technique can be found here.
In order to fix this issue we’ve removed the ability to define absolute paths in the Admin Control Panel. This resulted in the removal of setting the ImageMagick path, so make sure to have the GD image library available instead. A new event to generate thumbnails was added as replacement, so you’re able to write an extension that uses a different image library to generate thumbnails. We would like to thank Simon Scannell and Robin Peraglie of RIPS Technologies for their report and responsible disclosure. The issue has been assigned CVE-2018-19274.
The fixed issues include, among others, compatibility issues with PHP 7.2 and issues with removing users from the newly registered user group more than once.
Among the notable changes are the addition of the list-unsubscribe header to emails sent by phpBB and the ability to reset your password without entering the username.
Powered by phpBB™ • Design by PlanetStyles phpBB Persian پشتیبانی فارسی Optimized by: phpBB SEO Time: 0.083s | Peak Memory Usage: 2.49 MIB | GZIP: Off | Queries: 30