<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[PunBB Forums - PunBB 1.2.18]]></title>
	<link rel="self" href="http://punbb.informer.com/forums/feed/atom/topic/19534/"/>
	<updated>2008-07-12T13:38:27Z</updated>
	<generator>PunBB</generator>
	<id>http://punbb.informer.com/forums/topic/19534/punbb-1218/</id>
		<entry>
			<title type="html"><![CDATA[Re: PunBB 1.2.18]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/116651/#p116651"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>hcgtv wrote:</cite><blockquote><p>The <a href="http://punbb.informer.com/trac/changeset/248">PunBB trunk copyrights update</a> makes the changed files zip contain more files than were actually changed due to issues found.</p><p>I think it would be better to have the changed files zip only to contain what files need updating, this would speed up the adoption of these security patches.</p></blockquote></div><p>I agree with your arguments, but we cannot release new version of PunBB with illegal copyrights. And we can&#039;t put all of them to &quot;changed files only&quot; zip, because users will have different sources then.</p><div class="quotebox"><cite>hcgtv wrote:</cite><blockquote><p>Also, should this release announcement be on the front page?</p></blockquote></div><p>Yup. You&#039;re right :)</p>]]></content>
			<author>
				<name><![CDATA[Anatoly]]></name>
				<uri>http://punbb.informer.com/forums/user/12152/</uri>
			</author>
			<updated>2008-07-12T13:38:27Z</updated>
			<id>http://punbb.informer.com/forums/post/116651/#p116651</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: PunBB 1.2.18]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/116645/#p116645"/>
			<content type="html"><![CDATA[<p>Anatoly,</p><p>The <a href="http://punbb.informer.com/trac/changeset/248">PunBB trunk copyrights update</a> makes the changed files zip contain more files than were actually changed due to issues found.</p><p>I think it would be better to have the changed files zip only to contain what files need updating, this would speed up the adoption of these security patches.</p><p>Also, should this release announcement be on the front page?</p><p>Thanks.</p>]]></content>
			<author>
				<name><![CDATA[hcgtv]]></name>
				<uri>http://punbb.informer.com/forums/user/1461/</uri>
			</author>
			<updated>2008-07-11T17:31:09Z</updated>
			<id>http://punbb.informer.com/forums/post/116645/#p116645</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[PunBB 1.2.18]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/116626/#p116626"/>
			<content type="html"><![CDATA[<p><span style="color: #CC0000">EDIT: Please, do update directly to PunBB 1.2.19 due to the parser bug introduced in 1.2.18.<br />Patches and changes files for 1.2.17 to 1.2.19 migration are available at <a href="http://punbb.informer.com/downloads.php#1.2.17">Downloads page</a>.</span></p><p>Just updated PunBB to 1.2.18.<br />Several security vulnerabilities fixed.</p><p>Changes:<br /></p><ul><li><p>Fixed an SMTP command injection vulnerability, discovered by Stefan Esser.<br /></p></li><li><p>Fixed an XSS issue in include/parser.php, discovered by Dan Crowley.</p></li><li><p>Fixed issue with database returning the same user on multiple pages of the userlist, noticed by hcgtv.</p></li><li><p>Fixed several potential XSS vectors in moderate.php.</p></li><li><p>Fixed the avatars of deleted users not being removed.</p></li><li><p>Copyrights and punbb.informer.com links updated.</p></li><li><p>Docs removed.</p></li></ul><p>It is strongly recommended to update your PunBB 1.2 installations as soon as possible.<br />Visit <a href="http://punbb.informer.com/downloads.php">Downloads page</a> for archives and the patch. Or get latest revision from <a href="http://punbb.informer.com/svn/punbb/trunk/">SVN trunk</a>.</p><p>Thanks to the people who reported issues and Smartys who fixed them.</p>]]></content>
			<author>
				<name><![CDATA[Anatoly]]></name>
				<uri>http://punbb.informer.com/forums/user/12152/</uri>
			</author>
			<updated>2008-07-11T13:35:43Z</updated>
			<id>http://punbb.informer.com/forums/post/116626/#p116626</id>
		</entry>
</feed>
