Koozali.org: home of the SME Server

Obsolete Releases => SME 6.x Contribs => Topic started by: simon101 on April 21, 2006, 02:32:18 PM

Title: Horde 3.0.9 Security issue
Post by: simon101 on April 21, 2006, 02:32:18 PM
Can anyone help me with a Horde security issue?
I have a server running for 2 weeks now and it has allready been tainted bij a worm!
Horde.org has a post on this:
________________________________________________________________
March 28th, 2006.
The Horde Team has released a critical security fix for the Horde Application Framework versions 3.0 and above. Version 2.x and earlier releases are not affected. The fixed Horde versions 3.0.10 and 3.1.1 are available. We strongly encourage every user to update to the new versions immediately.
________________________________________________________________

Can sombody make an update for Horde 3.0.9? (Maybe mr Bennett?)
Title: Re: Horde 3.0.9 Security issue
Post by: mrjhb3 on April 23, 2006, 08:33:02 AM
Quote from: "simon101"
Can anyone help me with a Horde security issue?
I have a server running for 2 weeks now and it has allready been tainted bij a worm!
Horde.org has a post on this:
________________________________________________________________
March 28th, 2006.
The Horde Team has released a critical security fix for the Horde Application Framework versions 3.0 and above. Version 2.x and earlier releases are not affected. The fixed Horde versions 3.0.10 and 3.1.1 are available. We strongly encourage every user to update to the new versions immediately.
________________________________________________________________

Can sombody make an update for Horde 3.0.9? (Maybe mr Bennett?)


Well, OK.  As soon as the mirrors sync, you can download and run the current install_horde30.sh file.

changes:
# April 24, 2006:       Added Horde 3.0.10 and gollem 1.0.2
Title: Thanx
Post by: simon101 on April 23, 2006, 01:29:49 PM
Thanx for the quick response!
Only, the Tar file that is on this directory has got a file size of 0 bytes..
http://mirror.contribs.org/smeserver/contribs//jbennett/horde30/

Friendly Greetings

Simon
Title: Re: Thanx
Post by: mrjhb3 on April 23, 2006, 03:56:14 PM
Quote from: "simon101"
Thanx for the quick response!
Only, the Tar file that is on this directory has got a file size of 0 bytes..
http://mirror.contribs.org/smeserver/contribs//jbennett/horde30/

Friendly Greetings

Simon


Must have been a bad sync.  1 of the 4 files I uploaded were correct.  I'll just re-upload them again.

JB
Title: Downloaded again and it works!
Post by: simon101 on April 23, 2006, 08:04:56 PM
Thanks again for the quick response.
Just to let you know, I've installed it and it works!
Title: Horde 3.0.9 Security issue
Post by: wellsi on May 01, 2006, 12:14:29 PM
Anyone using SME 6.x who has upgraded Webmail to use Horde 3 should read the news article http://no.longer.valid/news/article.php?storyid=103

Take action immediately and disable Webmail, then do one of

Thank You to John Bennett for making this Horde 3.0.10 update available.

Ian Wells