Security fix - PHlyMail 3.04.06 released

News about phlyMail and phlymail.com

Security fix - PHlyMail 3.04.06 released

Postby mso » 26.09.2006 22:47

This build fixes a potential security hole in PHlyMail. As far as we know, this just affects the file phlymail/handlers/email/mod.listmail.php under the presumption, that your server has the option register_globals set to "On".

We recommend, that all users of PHlyMail updater their installation as fast as possible.

The builds have been published in the usual places: under http://phlymail.de/en/phlymail/lite/download/ for PHlyMail Lite and in the customer service area for Personal Edition / MessageCenter. Additionally you can use the AutoUpdater to get your installation up to date.

The person who found this security problem unfortunately decided to publish an exploit instead of informing us directly.

It took as far under 30 minutes to fix the problem after acknowledgement of the bug and release this new build.
Matthias Sommerfeld

phlyMail Developer
http://phlymail.com
User avatar
mso
Site Admin
Site Admin
 
Posts: 1274
Joined: 01.11.2001 01:00
Location: Berlin

Return to Announcements and News

Who is online

Registered users: No registered users

cron