En

phpBB官网安全更新(2020-08-07)

来源:phpBB官网 发布日期:2020-08-07 阅读次数:2339 评论:0

基本信息

发布日期:2020-08-07(官方当地时间)

更新类型:安全更新

更新版本:3.3.1

感知时间:2020-08-08 04:11:29

风险等级:未知

情报贡献:TSRC

更新标题

phpBB 3.3.1 Release - Please Update

更新详情

Greetings everyone,



We are pleased to announce the release of phpBB 3.3.1 "Bertie’s Twenty". This version is a maintenance and security release of the 3.3.x branch which fixes one security issue, introduces further hardening, and resolves various issues reported in previous versions.



Previous versions of phpBB did allow limiting the dimensions of images posted. This could however also be used to e.g. check for the existence of services that should only be accessible from the internal network. We would like to thank FVD for reporting this issue to us via hackerone. The issue has been assigned CVE-2020-8226.



The fixed issues include, among others, issues with using Emojis in multiple text fields, the inability to delete or mark PMs read in the UCP folder view, issues with resetting a password, and a slow search on PostgreSQL. The amount of emails sent for notifications related to topics have been improved and new and improved enable and disable mechanisms for newer profile field types have been integrated. We would like to dedicate this last addition to javiexin.



The full list of changes is available in the changelog file within the docs folder contained in the release package. You can find the key highlights of this release on the wiki at https://wiki.phpbb.com/Release_Highlights/3.3.1 and a list of all issues fixed on our tracker at https://tracker.phpbb.com/issues/?filter=15291



The packages can be downloaded from our downloads page.



The development team thanks everyone who contributed code to this release: 3D-I, kasimi, rxu, Dark❶, KYPREO, Alfredo Ramos, JoshyPHP, javiexin, Jakub Senko, ansavin, Bob Weinand, Kidounet, MichaIng, hubaishan, ioannisbat, phpBB España



If you have any questions or comments, we'll be happy to address them in the discussion topic.



- The phpBB Team

软件描述

phpBB是一个论坛软件,使用PHP语言开发的并开放其原始码

CVE编号

TSRC分析

暂无

业界资讯

暂无

评论

提交评论 您输入的评论有误,请重新输入