New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hello,

Several security flaws have been recently identified in SPIP
(Thank you to William Farner, Arnault Pachot Silvere Cainaud,
Maxime Pelletier, Anthony and Christopher Cervoise Imberti).
They are corrected in newest versions 1.9.2.o, 2.0.18 and 2.1.13.

Most of them relate to potential XSS injection vulnerabilities.

The use of the updated safety screen protects most flaws:
you are encouraged to download its most recent version
(1.0.10 April 17, 2012) and copy the file in your config/ directory
(cf. http://www.spip.net/en_article4201.html).

However, as all the flaws are not corrected by the safety screen,
we strongly recommend to update SPIP with the newest versions.

Feel free to use the various resources provided by the
community to help in this update:

We remind that the best way to report a security vulnerability is to send an email
to spip-team@rezo.net.

How to update?

  1. with spip_loader.php:
    if you have already installed SPIP with spip_loader, go to the url
    http://YOUR_SITE/spip_loader.php
    to install SPIP 2.1.13

  2. by copying the files:
    SPIP 2.1.13 is available at
    http://files.spip.org/spip/stable/spip.zip

  3. SVN:
    if you are in the branch 2.1, just do a « svn up »
    svn://trac.rezo.net/spip/branches/spip-2.1
    The version 2.1.13 is also available in the branch
    svn://trac.rezo.net/spip/branches/spip-2-stable
    and in the tag
    svn://trac.rezo.net/spip/tags/spip-2.1.13

Versions 2.0.18 and 1.9.2.o are available here:
http://files.spip.org/spip/archives/

Postscript:

How can I be kept informed of these announces? The simplest way is to
subscribe to the mailing list
http://listes.rezo.net/mailman/listinfo/spip-ann

Of course social networks are not left out:

.Gilles

Hello,
I have updated with version 2.1.13 and I find one thing:
When I want to upload an image, It doesn’t show successful upload. But when I save the article and modify it again, I see the image icon that has been uploaded. Is it maybe a bug?
Kamran


From: Gilles Vincent gilles.vincent@gmail.com
To: spip-en spip-en@rezo.net
Sent: Monday, April 23, 2012 1:42 AM
Subject: [Spip-en] New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hello,

Several security flaws have been recently identified in SPIP
(Thank you to William Farner, Arnault Pachot Silvere Cainaud,
Maxime Pelletier, Anthony and Christopher Cervoise Imberti).
They are corrected in newest versions 1.9.2.o, 2.0.18 and 2.1.13.

Most of them relate to potential XSS injection vulnerabilities.

The use of the updated safety screen protects most flaws:
you are encouraged to download its most recent version
(1.0.10 April 17, 2012) and copy the file in your config/ directory
(cf. http://www.spip.net/en_article4201.html).

However, as all the flaws are not corrected by the safety screen,
we strongly recommend to update SPIP with the newest versions.

Feel free to use the various resources provided by the
community to help in this update:

We remind that the best way to report a security vulnerability is to send an email
to spip-team@rezo.net.

How to update?

  1. with spip_loader.php:
    if you have already installed SPIP with spip_loader, go to the url
    http://YOUR_SITE/spip_loader.php
    to install SPIP 2.1.13

  2. by copying the files:
    SPIP 2.1.13 is available at
    http://files.spip.org/spip/stable/spip.zip

  3. SVN:
    if you are in the branch 2.1, just do a « svn up »
    svn://trac.rezo.net/spip/branches/spip-2.1
    The version 2.1.13 is also available in the branch
    svn://trac.rezo.net/spip/branches/spip-2-stable
    and in the tag
    svn://trac.rezo.net/spip/tags/spip-2.1.13

Versions 2.0.18 and 1.9.2.o are available here:
http://files.spip.org/spip/archives/

Postscript:

How can I be kept informed of these announces? The simplest way is to
subscribe to the mailing list
http://listes.rezo.net/mailman/listinfo/spip-ann

Of course social networks are not left out:

.Gilles


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en

Hi,
it’s a bug that has been corrected after the release :

remplace prive/javascript/async_upload.js par
http://core.spip.org/projects/spip/repository/revisions/19308/raw/branches/spip-2.1/prive/javascript/async_upload.js

.Gilles

On Sat, Apr 28, 2012 at 8:52 AM, kamran Mir Hazar <kamran_mirhazar@yahoo.com> wrote:

Hello,
I have updated with version 2.1.13 and I find one thing:
When I want to upload an image, It doesn’t show successful upload. But when I save the article and modify it again, I see the image icon that has been uploaded. Is it maybe a bug?
Kamran


From: Gilles Vincent <gilles.vincent@gmail.com>
To: spip-en <spip-en@rezo.net>
Sent: Monday, April 23, 2012 1:42 AM
Subject: [Spip-en] New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hello,

Several security flaws have been recently identified in SPIP
(Thank you to William Farner, Arnault Pachot Silvere Cainaud,
Maxime Pelletier, Anthony and Christopher Cervoise Imberti).
They are corrected in newest versions 1.9.2.o, 2.0.18 and 2.1.13.

Most of them relate to potential XSS injection vulnerabilities.

The use of the updated safety screen protects most flaws:
you are encouraged to download its most recent version
(1.0.10 April 17, 2012) and copy the file in your config/ directory
(cf. http://www.spip.net/en_article4201.html).

However, as all the flaws are not corrected by the safety screen,
we strongly recommend to update SPIP with the newest versions.

Feel free to use the various resources provided by the
community to help in this update:

We remind that the best way to report a security vulnerability is to send an email
to spip-team@rezo.net.

How to update?

  1. with spip_loader.php:
    if you have already installed SPIP with spip_loader, go to the url
    http://YOUR_SITE/spip_loader.php
    to install SPIP 2.1.13

  2. by copying the files:
    SPIP 2.1.13 is available at
    http://files.spip.org/spip/stable/spip.zip

  3. SVN:
    if you are in the branch 2.1, just do a « svn up »
    svn://trac.rezo.net/spip/branches/spip-2.1
    The version 2.1.13 is also available in the branch
    svn://trac.rezo.net/spip/branches/spip-2-stable
    and in the tag
    svn://trac.rezo.net/spip/tags/spip-2.1.13

Versions 2.0.18 and 1.9.2.o are available here:
http://files.spip.org/spip/archives/

Postscript:

How can I be kept informed of these announces? The simplest way is to
subscribe to the mailing list
http://listes.rezo.net/mailman/listinfo/spip-ann

Of course social networks are not left out:

.Gilles


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en

Hi,
I have replaced that file, but still I have the same issue.
Kamran


From: Gilles Vincent gilles.vincent@gmail.com
To: kamran Mir Hazar kamran_mirhazar@yahoo.com
Cc: spip-en spip-en@rezo.net
Sent: Saturday, April 28, 2012 9:20 AM
Subject: Re: [Spip-en] New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hi,
it’s a bug that has been corrected after the release :

remplace prive/javascript/async_upload.js par
http://core.spip.org/projects/spip/repository/revisions/19308/raw/branches/spip-2.1/prive/javascript/async_upload.js

.Gilles

On Sat, Apr 28, 2012 at 8:52 AM, kamran Mir Hazar <kamran_mirhazar@yahoo.com> wrote:

Hello,
I have updated with version 2.1.13 and I find one thing:
When I want to upload an image, It doesn’t show successful upload. But when I save the article and modify it again, I see the image icon that has been uploaded. Is it maybe a bug?
Kamran


From: Gilles Vincent <gilles.vincent@gmail.com>
To: spip-en <spip-en@rezo.net>
Sent: Monday, April 23, 2012 1:42 AM
Subject: [Spip-en] New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hello,

Several security flaws have been recently identified in SPIP
(Thank you to William Farner, Arnault Pachot Silvere Cainaud,
Maxime Pelletier, Anthony and Christopher Cervoise Imberti).
They are corrected in newest versions 1.9.2.o, 2.0.18 and 2.1.13.

Most of them relate to potential XSS injection vulnerabilities.

The use of the updated safety screen protects most flaws:
you are encouraged to download its most recent version
(1.0.10 April 17, 2012) and copy the file in your config/ directory
(cf. Security screen - SPIP).

However, as all the flaws are not corrected by the safety screen,
we strongly recommend to update SPIP with the newest versions.

Feel free to use the various resources provided by the
community to help in this update:

We remind that the best way to report a security vulnerability is to send an email
to spip-team@rezo.net.

How to update?

  1. with spip_loader.php:
    if you have already installed SPIP with spip_loader, go to the url
    http://YOUR_SITE/spip_loader.php
    to install SPIP 2.1.13

  2. by copying the files:
    SPIP 2.1.13 is available at
    http://files.spip.org/spip/stable/spip.zip

  3. SVN:
    if you are in the branch 2.1, just do a « svn up »
    svn://trac.rezo.net/spip/branches/spip-2.1
    The version 2.1.13 is also available in the branch
    svn://trac.rezo.net/spip/branches/spip-2-stable
    and in the tag
    svn://trac.rezo.net/spip/tags/spip-2.1.13

Versions 2.0.18 and 1.9.2.o are available here:
SPIP-Contrib

Postscript:

How can I be kept informed of these announces? The simplest way is to
subscribe to the mailing list
http://listes.rezo.net/mailman/listinfo/spip-ann

Of course social networks are not left out:

.Gilles


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en

Hi!

What browser do use? I have the same matter but rather rarely with Opera.
I could not detect the dependence.
It seems that the matters mostly depends on the hosting configuration, the way SPIP was installed, the instelled plugins and Moon phase.

But I face this very rarely and only with Opera browser.

Best regards,
Serge

2012/4/28 kamran Mir Hazar <kamran_mirhazar@yahoo.com>

Hi,
I have replaced that file, but still I have the same issue.
Kamran


From: Gilles Vincent <gilles.vincent@gmail.com>

To: kamran Mir Hazar <kamran_mirhazar@yahoo.com>
Cc: spip-en <spip-en@rezo.net>
Sent: Saturday, April 28, 2012 9:20 AM
Subject: Re: [Spip-en] New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hi,
it’s a bug that has been corrected after the release :

remplace prive/javascript/async_upload.js par
http://core.spip.org/projects/spip/repository/revisions/19308/raw/branches/spip-2.1/prive/javascript/async_upload.js

.Gilles

On Sat, Apr 28, 2012 at 8:52 AM, kamran Mir Hazar <kamran_mirhazar@yahoo.com> wrote:

Hello,
I have updated with version 2.1.13 and I find one thing:
When I want to upload an image, It doesn’t show successful upload. But when I save the article and modify it again, I see the image icon that has been uploaded. Is it maybe a bug?
Kamran


From: Gilles Vincent <gilles.vincent@gmail.com>
To: spip-en <spip-en@rezo.net>
Sent: Monday, April 23, 2012 1:42 AM
Subject: [Spip-en] New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hello,

Several security flaws have been recently identified in SPIP
(Thank you to William Farner, Arnault Pachot Silvere Cainaud,
Maxime Pelletier, Anthony and Christopher Cervoise Imberti).
They are corrected in newest versions 1.9.2.o, 2.0.18 and 2.1.13.

Most of them relate to potential XSS injection vulnerabilities.

The use of the updated safety screen protects most flaws:
you are encouraged to download its most recent version
(1.0.10 April 17, 2012) and copy the file in your config/ directory
(cf. http://www.spip.net/en_article4201.html).

However, as all the flaws are not corrected by the safety screen,
we strongly recommend to update SPIP with the newest versions.

Feel free to use the various resources provided by the
community to help in this update:

We remind that the best way to report a security vulnerability is to send an email
to spip-team@rezo.net.

How to update?

  1. with spip_loader.php:
    if you have already installed SPIP with spip_loader, go to the url
    http://YOUR_SITE/spip_loader.php
    to install SPIP 2.1.13

  2. by copying the files:
    SPIP 2.1.13 is available at
    http://files.spip.org/spip/stable/spip.zip

  3. SVN:
    if you are in the branch 2.1, just do a « svn up »
    svn://trac.rezo.net/spip/branches/spip-2.1
    The version 2.1.13 is also available in the branch
    svn://trac.rezo.net/spip/branches/spip-2-stable
    and in the tag
    svn://trac.rezo.net/spip/tags/spip-2.1.13

Versions 2.0.18 and 1.9.2.o are available here:
http://files.spip.org/spip/archives/

Postscript:

How can I be kept informed of these announces? The simplest way is to
subscribe to the mailing list
http://listes.rezo.net/mailman/listinfo/spip-ann

Of course social networks are not left out:

.Gilles


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en

Hi,
I use Firefox mostly. The problem that I had is over now. Maybe it was because of the cache. I don’t know really.

Kamran


From: Serge Markitanenko serge.markitanenko@gmail.com
To: kamran Mir Hazar kamran_mirhazar@yahoo.com; spip-en@rezo.net
Sent: Thursday, May 3, 2012 8:32 AM
Subject: Re: [Spip-en] New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hi!

What browser do use? I have the same matter but rather rarely with Opera.
I could not detect the dependence.
It seems that the matters mostly depends on the hosting configuration, the way SPIP was installed, the instelled plugins and Moon phase.

But I face this very rarely and only with Opera browser.

Best regards,
Serge

2012/4/28 kamran Mir Hazar <kamran_mirhazar@yahoo.com>

Hi,
I have replaced that file, but still I have the same issue.
Kamran


From: Gilles Vincent <gilles.vincent@gmail.com>

To: kamran Mir Hazar <kamran_mirhazar@yahoo.com>
Cc: spip-en <spip-en@rezo.net>
Sent: Saturday, April 28, 2012 9:20 AM
Subject: Re: [Spip-en] New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hi,
it’s a bug that has been corrected after the release :

remplace prive/javascript/async_upload.js par
http://core.spip.org/projects/spip/repository/revisions/19308/raw/branches/spip-2.1/prive/javascript/async_upload.js

.Gilles

On Sat, Apr 28, 2012 at 8:52 AM, kamran Mir Hazar <kamran_mirhazar@yahoo.com> wrote:

Hello,
I have updated with version 2.1.13 and I find one thing:
When I want to upload an image, It doesn’t show successful upload. But when I save the article and modify it again, I see the image icon that has been uploaded. Is it maybe a bug?
Kamran


From: Gilles Vincent <gilles.vincent@gmail.com>
To: spip-en <spip-en@rezo.net>
Sent: Monday, April 23, 2012 1:42 AM
Subject: [Spip-en] New stable releases SPIP 1.9.2o, 2.0.18 et 2.1.13 are availables

Hello,

Several security flaws have been recently identified in SPIP
(Thank you to William Farner, Arnault Pachot Silvere Cainaud,
Maxime Pelletier, Anthony and Christopher Cervoise Imberti).
They are corrected in newest versions 1.9.2.o, 2.0.18 and 2.1.13.

Most of them relate to potential XSS injection vulnerabilities.

The use of the updated safety screen protects most flaws:
you are encouraged to download its most recent version
(1.0.10 April 17, 2012) and copy the file in your config/ directory
(cf. Security screen - SPIP).

However, as all the flaws are not corrected by the safety screen,
we strongly recommend to update SPIP with the newest versions.

Feel free to use the various resources provided by the
community to help in this update:

We remind that the best way to report a security vulnerability is to send an email
to spip-team@rezo.net.

How to update?

  1. with spip_loader.php:
    if you have already installed SPIP with spip_loader, go to the url
    http://YOUR_SITE/spip_loader.php
    to install SPIP 2.1.13

  2. by copying the files:
    SPIP 2.1.13 is available at
    http://files.spip.org/spip/stable/spip.zip

  3. SVN:
    if you are in the branch 2.1, just do a « svn up »
    svn://trac.rezo.net/spip/branches/spip-2.1
    The version 2.1.13 is also available in the branch
    svn://trac.rezo.net/spip/branches/spip-2-stable
    and in the tag
    svn://trac.rezo.net/spip/tags/spip-2.1.13

Versions 2.0.18 and 1.9.2.o are available here:
SPIP-Contrib

Postscript:

How can I be kept informed of these announces? The simplest way is to
subscribe to the mailing list
http://listes.rezo.net/mailman/listinfo/spip-ann

Of course social networks are not left out:

.Gilles


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en


spip-en@rezo.net - http://listes.rezo.net/mailman/listinfo/spip-en