phpBB 3.0.7-PL1 released
We are sorry to announce the immediate release of phpBB 3.0.7-PL1 to address a security issue which was introduced in 3.0.7, unfortunately the issue wasn’t noticed during testing and has only surfaced a week after the release of 3.0.7.
We promised working feeds for phpBB 3.0.7. Sadly, we were not able to deliver on that promise – a critical bug in the permission handling for feeds slipped past. To all people who already have updated to 3.0.7, it is of critical importance to update to 3.0.7-PL1. Otherwise, it is possible for users to bypass permission settings under the following circumstances:
– Feeds are enabled
The fix for the issue is a single line change inside of feed.php, line 525 has changed from:
$forum_ids = array_keys($auth->acl_getf(‘f_read’));
There were no other changes, in particular neither style nor language changes.
The original announcement is located at:
A short explanation of how to do a conversion, installation or update is included within the provided INSTALL.html file, please be sure to read it. You can find a list of requirements on our Downloads page:
If you find any security issues please report them to our security tracker:
If you experience problems with the automatic update (white screens, timeouts, etc.) we recommend using the “changed files only” or “patch” method for updating.
Full Package: Full phpBB 3 source code and english language files.
Automatic Update Package: Update package for the automatic updater, contains changes from previous release to this release.
Changed Files Only: Complete files, but only those that were changed since previous releases of phpBB 3. This archive contains changed files for every previous release.
Patch Files: This file contains diffs against the previous phpBB 3 release, which can be applied with the patch utility.
Select the package most suitable for you. We recommend the following methods depending on your situation:
– For new installations you should use the Full Package
*Please ensure you read the INSTALL and README documents in docs/ before proceeding with installation, updates or conversions!*
The download is of course available on our downloads page:
Our release archive provides all packages we build. If you do not find your desired package you can probably find it in the release archive.
These are the files with their md5 sums:
*Download & Documentation*
phpBB Downloads – http://www.phpbb.com/downloads/
Comments are closed.