Help - Search - Members - Calendar
Full Version: Coppermine 1.4.14
TotalChoice Hosting Family Forums > TotalChoice Hosting General Support > Security Discussions > Software/Scripts/Other Alerts
TCH-Thomas
A security update for Coppermine have been released.

Read more / Get it at: coppermine-gallery.net/forum/index.php?topic=48106.0
TCH-Bruce
Thanks Thomas
samserv
Regarding this update.

I had trouble and got exploited. TCH promptly notified me as usual to the problem. I updated through Fantastico. Well that only updates to 1.4.12. Why does TCH use fantastico if updates ar so far behind? I thought that I was fine until I got another notice that that account had been exploited again and I went looking and noticed that coppermine had released 2 updates beyond what was available in fantastico.

The side issue to this is once you manually update Fantastico can no longer be used to update applications because it reports that the wrong version, the old one, is still installed. Not a gripe here just a questions. Fantastico is so nice because i have multiple reseller accounts that have coppermine and other scripts. Fantastico made updating them so easy.

Pat
SamServ Web Design
TCH-Bruce
TCH has no control over when Fantastico updates the scripts it installs. Fantastico is getting better at keeping updated but there will be times when they are behind.

I still prefer to install my scripts manually.
samserv
QUOTE (TCH-Bruce @ Dec 13 2007, 08:16 PM) *
TCH has no control over when Fantastico updates the scripts it installs. Fantastico is getting better at keeping updated but there will be times when they are behind.

I still prefer to install my scripts manually.


Thanks Bruce. I was mistakenly under the impression that TCH managed what was available under Fantastico. I don't know if it is possible but It would be nice to have a small warning in the Fantastico interface that alluded to the fact that the scripts there may not be the latest available and thus a user may be open to exploits. I sure learned my lesson. NO MORE FANTASTICO for me.

And as always TCH Gurus were wonderful! Props to you guys for catching it and being very nice about me allowing an exploit on the servers. I am sure that is a thankless job most of the time. But I APPRECIATE IT.

Pat
SamSERV Web Design
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.