[pmwiki-users] PmWiki 2.2.33 released: Security update

Petko Yotov 5ko at 5ko.fr
Fri Sep 23 02:44:04 CDT 2011


Hello. PmWiki version 2.2.33 was published today, and is available at:

  http://www.pmwiki.org/pub/pmwiki/pmwiki-2.2.33.tgz
  http://www.pmwiki.org/pub/pmwiki/pmwiki-2.2.33.zip
   svn://www.pmwiki.org/pmwiki/tags/latest

This version fixes a security issue introduced in 2.2.32 which left the groups 
Site and SiteAdmin open for reading and editing because the pages 
Site.GroupAttributes and SiteAdmin.GroupAttributes didn't have all necessary 
attributes (the "site" read and edit permissions applied).

All wikis running 2.2.32 should upgrade. If you cannot immediately upgrade, 
you can set the attributes from your wiki:

* open the attributes page [[SiteAdmin.GroupAttributes?action=attr]] and set
  a "read" and an "edit" password,  @lock  is recommended.
* open the attributes page [[Site.GroupAttributes?action=attr]] and set an
  "edit" password,  @lock  is recommended. Do not set a "read" password here. 

The release also fixes the refcount.php script to produce valid HTML, and 
updates intermap.txt entries PITS: and Wikipedia: to point to their current 
locations.

Thanks,
Petko
--
Change log     :  http://www.pmwiki.org/wiki/PmWiki/ChangeLog
Release notes  :  http://www.pmwiki.org/wiki/PmWiki/ReleaseNotes
If you upgrade :  http://www.pmwiki.org/wiki/PmWiki/Upgrades



More information about the pmwiki-users mailing list